Skip to content

Add comments on risky permissions#1468

Merged
bennothommo merged 4 commits intodevelopfrom
fix/administrative-permissions
Mar 14, 2026
Merged

Add comments on risky permissions#1468
bennothommo merged 4 commits intodevelopfrom
fix/administrative-permissions

Conversation

@bennothommo
Copy link
Member

@bennothommo bennothommo commented Mar 13, 2026

To assist admins when assigning permissions to users, I have added comments to permissions that should only be given to trusted users. These permissions, if given to untrusted users, may pose a security risk due to being able to negatively manipulate the experience of other users, or could be potentially used to grant themselves more access than intended.

image

Summary by CodeRabbit

  • New Features

    • Permission comments now appear as tooltip-enabled info icons next to permission labels for clearer explanations.
  • Documentation

    • Updated permission labels and added descriptive notes covering unsafe Markdown, administrator/impersonation rights, branding, and CMS permissions to clarify access implications.

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance PRs that fix bugs, are translation changes or make only minor changes needs review Issues/PRs that require a review from a maintainer

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants