Skip to content

Restrict who can see or change a system-wide configuration #9

Description

@mlopezFC

The problem

System-wide configurations are all-or-nothing: anyone who can reach the configuration view can see and change every one of them. Some settings are ordinary operational knobs, and others — credentials, integration endpoints, limits with billing consequences — are not.

What we have in mind

Per-configuration security constraints, so that visibility and editability can each be restricted to a set of roles. A configuration a user cannot edit should be visible read-only or hidden entirely, depending on how it is declared.


Opened from our own backlog when this tracker went public. If you need this, say so — comments and concrete use cases are what move something up the list.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions