Skip to content

Review own documents should not be possible #204

@tommylehmann

Description

@tommylehmann

According to documents/architecture-decisions.md Roles section a reviewer can list and view documents not created by himself. But if a user has the publisher or editor role as well as the reviewer role he can move his own advisory from Review to Approved.

It's not clear from the roles description but it seams wrong from a security point of view if someone can approve his own work. The review step is senseless unless you have enough people were one half is only allowed to write and the other only to review. This means the administrator must manage users that way that authors/editors/publishers and reviewers are disjoint groups. But then its not a peer review.

Is this intentional?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions