Give staff users and global group members administrator access to every org - #271
Merged
Merged
Conversation
…ry org
Users with is_staff set, or who belong to the group named by the new
SITE_GLOBAL_GROUP setting ("Global" by default), now see every active org
in the chooser and are treated as administrators on any org site, even
where they hold no role or a lesser one. Superuser-only views are
unaffected.
Claude-Session: https://claude.ai/code/session_01DUv4DmGrs25c9TwhzqmH81
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Users with
is_staffset, or who belong to the group named by the newSITE_GLOBAL_GROUPsetting ("Global"by default), are now treated as administrators of every org.has_global_access(user)helper, also available asUser.has_global_access(), cached on the user objectget_user_orgs()returns every active org for those users, so the org chooser lists them allOrg.get_user_org_group()resolves to the Administrators group for those users before checking the org's own admin/editor/viewer roles, so a lesser role on an org doesn't limit themNo view changes needed:
OrgPermsMixin,OrgObjPermsMixin, the chooser and theorg_permscontext processor all go through these functions. Superuser-only views (org list, users, etc.) are unaffected.Tests cover the helper,
get_user_orgs, org group resolution, and the chooser / org home / edit / manage accounts views for both a staff user and a global group member. AGlobalgroup is added to the test runner settings.