Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Certain roles shouldn't be able to create a store #5799

Open
pavlenex opened this issue Feb 28, 2024 · 3 comments
Open

Certain roles shouldn't be able to create a store #5799

pavlenex opened this issue Feb 28, 2024 · 3 comments

Comments

@pavlenex
Copy link
Contributor

Currently, no matter the role, every user can create a store within BTCPay Server, I think we need to reconsider that at some point.

@ndeet mentioned at some point that @Kukks told at a dev call that this is a limitation that should be addressed, but there was a technical reason (that I am unfamiliar with) on why it may not be easy.

Logging this one for future releases and something that may be relevant as we restructure roles.

@dennisreimann unsure how this plays out with recent role refactoring.

@dennisreimann
Copy link
Member

unsure how this plays out with recent role refactoring.

On #5719 it is still possible for everyone to create a store, but I think it would make sense to restrict that ability to the Owner role only. We can change this once #5782 is integrated.

@dstrukt
Copy link
Member

dstrukt commented Mar 1, 2024

ACK to restricting to the Owner role!

@pavlenex pavlenex added this to the 1.14.0 milestone Mar 14, 2024
@TChukwuleta
Copy link
Contributor

Hello.

Was looking at this issue. Since we are restricting role creation to owners role, was just thinking that it is just safe to not allow deletion of the owners role, as we do with all roles. What do you guys think?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Backlog 🪵
Development

No branches or pull requests

4 participants