🔥 High Priority: Implement Manifest-based Permissions Infrastructure
There probably needs to be a way to minimize the users that can view and edit some sections of volunteers,, participants, and staff. There are privacy issue, and potentially sensitive information contained in the ‘people’ records that not all those with manager role should have access to. ⏱️ Waiting for Kiz adjustments 💬 From Kiz: - Guardians and Participants should not be able to view the Person Detail page for anyone including themselves -- Or have access to /people (or person detail pages) or /horses (or horse detail pages) or /sessions (main list or session or series detail pages) -- Should also not be able to view session detail pages, even if they were a part of a session -- Dashboard, Photofeed, Notifs, and Settings only for them -- Dashboard session should not be clickable -- Past sessions should show their attendance status where we currently have the absent badge on the session row - Volunteers -- Should not be able to view the Person Detail page for anyone including themselves -- Or have access to /people (or person detail pages) or /sessions (main list or series detail pages) -- Should only be able to see sessions theyre assigned to (on roster for), the /horses page (without clickable horse cards - so they should not be able to see horse detail pages) Need reduced permissions for PersonDisplayName -- Should not be able to click and view any horse or person profile from the session detail pages or series detail pages (names are linked right now) -- Essentially entity detail pages for horses and people should blocked for participants -- Viewing /horses is okay, but shouldnt be able to click into any of the horse profiles -- Hide /people entirely for volunteers -- should not be able to view /sessions or series detail pages 🛠️ Fix: Implement a full role and type based permission infrastructure - 🧱 Infrastructure done - ⚙️ Working through integration and testing, starting with participants ✅ Implemented for : Volunteers as members, guardians, participants, and staff as members. - still need a full work up for staff as managers and volunteers as managers
There probably needs to be a way to minimize the users that can view and edit some sections of volunteers,, participants, and staff. There are privacy issue, and potentially sensitive information contained in the ‘people’ records that not all those with manager role should have access to. ⏱️ Waiting for Kiz adjustments 💬 From Kiz: - Guardians and Participants should not be able to view the Person Detail page for anyone including themselves -- Or have access to /people (or person detail pages) or /horses (or horse detail pages) or /sessions (main list or session or series detail pages) -- Should also not be able to view session detail pages, even if they were a part of a session -- Dashboard, Photofeed, Notifs, and Settings only for them -- Dashboard session should not be clickable -- Past sessions should show their attendance status where we currently have the absent badge on the session row - Volunteers -- Should not be able to view the Person Detail page for anyone including themselves -- Or have access to /people (or person detail pages) or /sessions (main list or series detail pages) -- Should only be able to see sessions theyre assigned to (on roster for), the /horses page (without clickable horse cards - so they should not be able to see horse detail pages) Need reduced permissions for PersonDisplayName -- Should not be able to click and view any horse or person profile from the session detail pages or series detail pages (names are linked right now) -- Essentially entity detail pages for horses and people should blocked for participants -- Viewing /horses is okay, but shouldnt be able to click into any of the horse profiles -- Hide /people entirely for volunteers -- should not be able to view /sessions or series detail pages 🛠️ Fix: Implement a full role and type based permission infrastructure - 🧱 Infrastructure done - ⚙️ Working through integration and testing, starting with participants ✅ Implemented for : Volunteers as members, guardians, participants, and staff as members. - still need a full work up for staff as managers and volunteers as managers
Roadmap status
Completed · New Feature