Page MenuHomePhabricator

Add a "Can Disable Users" capability to the "People" application
ClosedPublic

Authored by epriestley on Aug 27 2018, 1:58 PM.
Tags
None
Referenced Files
F18728716: D19606.id46871.diff
Tue, Sep 30, 9:44 AM
F18715212: D19606.id.diff
Mon, Sep 29, 9:25 AM
F18705999: D19606.diff
Sun, Sep 28, 2:31 PM
F18509764: D19606.id.diff
Sep 5 2025, 3:35 AM
F18503204: D19606.diff
Sep 4 2025, 10:54 PM
F18375050: D19606.id.diff
Aug 28 2025, 9:25 AM
F18362654: D19606.diff
Aug 27 2025, 2:43 PM
F18260178: D19606.id46871.diff
Aug 22 2025, 5:12 AM
Subscribers
None

Details

Summary

Depends on D19605. Ref T13189. See PHI642. This adds a separate "Can Disable Users" capability, and makes the underlying transaction use it.

This doesn't actually let you weaken the permission, since all pathways need more permissions:

  • user.edit needs CAN_EDIT.
  • user.disable/enable need admin.
  • Web UI workflow needs admin.

Upcoming changes will update these pathways.

Without additional changes, this does let you strengthen the permission.

This also fixes the inability to disable non-bot users via the web UI.

Test Plan
  • Set permission to "No One", tried to disable users. Got a tailored policy error.
  • Set permission to "All Users", disabled/enabled a non-bot user.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable