Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Limit administrator power #6

Open
1 of 3 tasks
celskeggs opened this issue Feb 9, 2020 · 3 comments
Open
1 of 3 tasks

Limit administrator power #6

celskeggs opened this issue Feb 9, 2020 · 3 comments
Assignees
Labels
P3 priority 3 (nice to have but doesn't block launch) privacy/security

Comments

@celskeggs
Copy link
Member

celskeggs commented Feb 9, 2020

We want uplink to be managed by a variety of people; we might consider removing problematic features like:

  • editing other peoples' posts

We might also want to add features like:

  • requiring two approvals for administrator actions
  • having an audit log
@gabrc52 gabrc52 added privacy/security P3 priority 3 (nice to have but doesn't block launch) labels Jan 9, 2023
@gabrc52
Copy link
Contributor

gabrc52 commented Jan 11, 2023

Matrix manages permissions through power levels, so a start is to find out how they work (for room permissions) (this would be best tracked in the moira integration issue (#2).

As for the administrators of the server itself, it would be good to implement something like that for administrator actions (things done with the admin API). For things that happen in rooms, events already work as an audit log of sorts. Who would this audit log be visible to?

This was referenced Jan 14, 2023
@gabrc52
Copy link
Contributor

gabrc52 commented Feb 15, 2023

  • Also something something FERPA(?)

@gabrc52
Copy link
Contributor

gabrc52 commented Aug 18, 2023

It is terrifyingly easy for an admin to silently login as any account so uhhh yes. This is important. I'll just think about it when more people join the project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
P3 priority 3 (nice to have but doesn't block launch) privacy/security
Projects
None yet
Development

No branches or pull requests

3 participants