fix: rbac: update of a step state is reserved to template owners only #307
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What kind of change does this PR introduce? (Bug fix, feature, docs update, ...)
Fix
What is the current behavior? (You can also link to an open issue here)
Previously, edition of the step state was allowed to resolvers. But
resolvers are regular users, that have the right to resolve the task,
they are not aware of the behaviour of the template.
What is the new behavior (if this is a feature change)?
This power should be reserved to template owners, who wrote the template, and know how the
steps state can be changed.
Does this PR introduce a breaking change? (What changes might users need to make in their application due to this PR?)
Yes: resolver users used to have the right to change the step state: this is now reserved to admins and
allowed_resolver_usernames
of thetask_template
.cc @simonmartinez in case RBAC need to be adapted on the UI