Page MenuHomePhabricator

In Phortune accounts, prevent self-removal more narrowly
ClosedPublic

Authored by epriestley on May 26 2020, 2:05 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Jan 6, 3:37 PM
Unknown Object (File)
Mon, Jan 6, 7:00 AM
Unknown Object (File)
Tue, Dec 31, 7:26 AM
Unknown Object (File)
Sun, Dec 22, 7:30 AM
Unknown Object (File)
Thu, Dec 19, 12:13 AM
Unknown Object (File)
Mon, Dec 16, 6:29 PM
Unknown Object (File)
Sun, Dec 15, 12:29 PM
Unknown Object (File)
Dec 8 2024, 6:54 PM
Subscribers
None

Details

Summary

Currently, Phortune attempts to prevent users from removing themselves as account managers. It does this by checking that the new list includes them.

Usually this is sufficient, because you can't normally edit an account unless you're already a manager. However, we get the wrong result (incorrect rejection of the edit) if the actor is omnipotent and the acting user was not already a member.

It's okay to edit an account into a state which doesn't include you if you have permission to edit the account and aren't already a manager.

Specifically, this supports more formal tooling around staff modifications to billing accounts, where the actor has staff-omnipotence and the acting user is a staff member and only used for purposes of leaving a useful audit trail.

Test Plan

Elsewhere, ran staff tooling to modify accounts and was able to act as "alice" to add "bailey", even though "alice" was not herself a manager.

Diff Detail

Repository
rP Phabricator
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

epriestley edited the summary of this revision. (Show Details)
This revision was not accepted when it landed; it landed in state Needs Review.May 26 2020, 2:09 PM
This revision was automatically updated to reflect the committed changes.