Skip to content

#8266: Security sensitive permissions (Lombiq Technologies: ORCH-214)#8874

Merged
BenedekFarkas merged 15 commits intoOrchardCMS:devfrom
Lombiq:issue/ORCH-214
Nov 27, 2025
Merged

#8266: Security sensitive permissions (Lombiq Technologies: ORCH-214)#8874
BenedekFarkas merged 15 commits intoOrchardCMS:devfrom
Lombiq:issue/ORCH-214

Conversation

@domonkosgabor
Copy link
Contributor

@domonkosgabor domonkosgabor commented Nov 26, 2025

Fixes: #8266

Here, I tried to mimic what we currently have in Orchard Core. It means we have a badge with the "Security Critical" text and a tooltip that reads "This permission could allow a user to elevate their other permissions. Grant it with extreme consideration.". It appears before each Allow checkbox when setting up a role's permissions. We also have a hint on that page describing the differences between the Allow and Effective settings.

In this PR, I have added the same hint to describe the Allow and Effective settings. We have an icon with an exclamation mark instead of a badge, and I used the exact text for the tooltip, as you can see in Orchard Core.

The tooltip text is the same as in Orchard Core.

I didn't want to include too much styling, so I used an icon from Font Awesome with the title HTML attribute.

@domonkosgabor domonkosgabor marked this pull request as ready for review November 26, 2025 14:06
@BenedekFarkas BenedekFarkas merged commit e5e71c7 into OrchardCMS:dev Nov 27, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security sensitive permissions

2 participants