-
Type:
Improvement
-
Resolution: Fixed
-
Affects Version/s: None
-
Component/s: Package Ex and Re-Import
-
High
-
None
-
Improve user permissions for Translator package export
-
None
-
Emptyshow more show less
Problem
We don't have good enough permission check for users attempt to export Translation package
Solution
Permissions for User roles:
Admin -> always
PM -> always
Simple Editor -> Never
Coordinator -> Coordinator Group Job of same step as Task should be open.
We have 3 PM types:
PM - omnipotent being so always allowed
Client PM - always allowed in tasks of his clients. For other clients he is simple editor
PM Light - only allowed in tasks where he is PM of a task
Additionally check for ACL permissions. This is needed to enable different handling depending on instance (client). Some may not want to allow Coordinators to export packages at all (that is already the case)
To actually implement it we have to introduce \MittagQI\Translate5\Task\ActionAssert\TaskAction::PackageExport action and action assert similar to: \MittagQI\Translate5\Task\ActionAssert\Permission\Assert\ExportPermissionAssert
Part of it already implemented in \editor_TaskController::assertTranslatorPackageAllowed
to extract it one may take a look at \MittagQI\Translate5\Task\ActionAssert\Permission\Assert\OpenPermissionAssert::canLoadAllTasks
this method was once extracted from controller as well
so this check can be safely moved to new assert to check simple system users.