KiOui/TOSTI

Noordcie / zuidcie shouldn't have view-user permissions

JobDoesburg opened this issue · 1 comments

We have 1290 TOSTI users with their credentials. That's quite a lot. I think it is good practice and data minimization to not give all staff users viewing permissions on these users.

Currently, noordcie and zuidcie members only have these permissions for manually creating orders and managing the blacklists.

In my opinion, they don't have to manually create orders linked to users (they can be anonymous or have a string field for name of the person that created them)

For the blacklists, we can implement a method to blacklist the person from a specific order.

Also, we should maybe write these fundamental design principles down somewhere in some README.md / CONTRIBUTING.md file.