A very good point. And good to hear “out loud”. This is the right way for me to be thinking about confidentiality and privacy.
I have used private categories with “less private” subcategories, so that a group can work in their space and publish things to a larger public. I guess this line of work will become obsolete by this change. So I should let users know that when they want to publish something, they need to move it to another, more public category. But then, how do they find their common work on this? I suppose they need to maintain a “publications” topic where they link the ‘more public’ topics. Any thoughts?
I am reviewing FIX: validate parent category/subcategories permissions by majakomel · Pull Request #6877 · discourse/discourse · GitHub by @maja.
The particular condition we are protecting against is:
- category (authors: read)
- subcategory (pilots: read)
What this means is that pilots are not allowed to see anything in the category yet have been granted permissions in the subcategory so something is fishy ![]()
The condition:
- category (authors: read)
- subcategory (pilots: read, authors: write)
Is still
after this new validation.
The tricky thing though
is that we no longer will allow:
- category (trust_level_3: read)
- subcategory (trust_level_4: write)
This particular edge case gives me pause, there is an easy enough work around … you would have to explicitly change
- category (trust_level_3: read, trust_level_4: read)
Given the OP is in a pretty bad state I say we see how the new restriction shakes up. FYI @HAWK @jomaxro
@sam PR がマージされたようですが、継承の機能性が私たちのインストールしている Discourse v2.4.0.beta2 +183 に反映されているかどうか確信が持てません。
サブカテゴリ内のすべてのコンテンツが、認証されていない一般ユーザーに対して latest 経由で即座に公開可能であることを知ったとき、私たちは非常に驚きました。
約 10 のカテゴリがあり、それぞれに多数のサブカテゴリがあるため、各カテゴリに対して手動で権限を設定するのは非常に手間がかかります。
@sam 現在は動作しているようですが、まだいくつかの端ケースが残っているようです(今日ちょっと困りました
)
サブカテゴリ作成時に「セキュリティ」タブですべての権限を削除することができ、その場合、(スタッフカテゴリなどの)サブカテゴリが正常に作成され、全員に可視化されてしまいます。
このオプションがどこかで有効になっているか確認するためにフォローアップしていますか? カテゴリの権限を変更し、すべてのサブカテゴリがその新しい権限を継承する方法はありますか?