Default security rules on extension : change for bundle
Hello all,
As of today, a ContentAdmin have by default the right to delete any extension, including ones in the Dashboard or Visualization Bundle. This can lead to big issues.
What I suggest : -default rule "ContentAdmin" : do not include extension here
-2 new custom rules : resource Extension_* name : Extension_Content_Admin_no_bundle_all_rights user.roles="ContentAdmin" and (resource.@ExtensionBundle!="Dashboard-bundle" and resource.@ExtensionBundle!="Visualization-bundle") with all rights
resource Extension_* name :Extension_Root_Admin_bundle user.roles="RootAdmin" and (resource.@ExtensionBundle="Dashboard-bundle" or resource.@ExtensionBundle="Visualization-bundle") with all rights
A new meme for your collection :
Best regards,
Simon
Bi Consultant (Dataviz & Dataprep) @ Business & Decision
NOTE: Upon clicking this link 2 tabs may open - please feel free to close the one with a login page. If you only see 1 tab with the login page, please try clicking this link first: Authenticate me! then try the link above again. Ensure pop-up blocker is off.