Page MenuHomePhabricator

Allow "Can Configure Application" permissions to be configured

Authored by epriestley on Nov 17 2018, 7:10 PM.



Ref T13216. See PHI980. Currently, each application in ApplicationsXConfigure has a "Can Configure Application" permission which is hard-coded to "Administrators".

There's no technical reason for this, there just hasn't been a great use case for unlocking it. I think when I originally wrote it our protections against locking yourself out of things weren't that great (i.e., it was easier to set the policy to something that prevented you from editing it after the new policy took effect). Our protections are better now.

The major goal here is to let installs open up Custom Forms for given applications (mostly Maniphest) to more users, but the other options mostly go hand-in-hand with that.

Also, in developer mode, include stack traces for policy exceptions. This makes debugging weird stuff (like the indirect Config application errors here) easier.

Test Plan
  • Granted "Can Configure Application" for Maniphest to all users.
  • Edited custom forms as a non-administrator.
  • Configured Maniphest as a non-administrator.
  • Installed/uninstalled Maniphest as a non-administrator.
  • Tried to lock myself out (got an error message).

Diff Detail

rP Phabricator
Automatic diff as part of commit; lint not applicable.
Automatic diff as part of commit; unit tests not applicable.

Event Timeline

epriestley created this revision.Nov 17 2018, 7:10 PM
epriestley requested review of this revision.Nov 17 2018, 7:12 PM
joshuaspence accepted this revision.Nov 19 2018, 1:21 AM

I feel like custom forms should have their own edit permissions can that access can be managed more granularly.

This revision is now accepted and ready to land.Nov 19 2018, 1:21 AM
This revision was automatically updated to reflect the committed changes.