mirror of
https://github.com/BookStackApp/BookStack.git
synced 2026-05-04 18:08:46 +03:00
Permissions Feature Requests #192
Closed
opened 2026-02-04 17:34:05 +03:00 by OVERLORD
·
2 comments
No Branch/Tag Specified
development
l10n_development
release
v26-03
ci_fixing
codeberg-actions
lexical_may_2026
MilnerMart/development
sort_rule_text
GamerClassN7/impersonations-for-admin
Zhey-on/feature/csp-image-css-controls-6033
tortillas5/development
clauvaldez/mfaReset
llm_only
vectors
McTom234/oidc-key-algorithms
docker_env
drawio_rendering
user_permissions
ldap_host_failover
svg_image
prosemirror
captcha_example
fix/video-export
v26.03.4
v26.03.3
v26.03.2
v26.03.1
v26.03
v25.12.9
v25.12.8
v25.12.7
v25.12.6
v25.12.5
v25.12.4
v25.12.3
v25.12.2
v25.12.1
v25.12
v25.11.6
v25.11.5
v25.11.4
v24.11.4
v25.11.3
v25.11.2
v25.11.1
v25.11
v25.07.3
v25.07.2
v25.07.1
v25.07
v25.05.2
v25.05.1
v25.05
v25.02.5
v25.02.4
v25.02.3
v25.02.2
v25.02.1
v25.02
v24.12.1
v24.12
v24.10.3
v24.10.2
v24.10.1
v24.10
v24.05.4
v24.05.3
v24.05.2
v24.05.1
v24.05
v24.02.3
v24.02.2
v24.02.1
v24.02
v23.12.3
v23.12.2
v23.12.1
v23.12
v23.10.4
v23.10.3
v23.10.2
v23.10.1
v23.10
v23.08.3
v23.08.2
v23.08.1
v23.08
v23.06.2
v23.06.1
v23.06
v23.05.2
v23.05.1
v23.05
v23.02.3
v23.02.2
v23.02.1
v23.02
v23.01.1
v23.01
v22.11.1
v22.11
v22.10.2
v22.10.1
v22.10
v22.09.1
v22.09
v22.07.3
v22.07.2
v22.07.1
v22.07
v22.06.2
v22.06.1
v22.06
v22.04.2
v22.04.1
v22.04
v22.03.1
v22.03
v22.02.3
v22.02.2
v22.02.1
v22.02
v21.12.5
v21.12.4
v21.12.3
v21.12.2
v21.12.1
v21.12
v21.11.3
v21.11.2
v21.11.1
v21.11
v21.10.3
v21.10.2
v21.10.1
v21.10
v21.08.6
v21.08.5
v21.08.4
v21.08.3
v21.08.2
v21.08.1
v21.08
v21.05.4
v21.05.3
v21.05.2
v21.05.1
v21.05
v21.04.6
v21.04.5
v21.04.4
v21.04.3
v21.04.2
v21.04.1
v21.04
v0.31.8
v0.31.7
v0.31.6
v0.31.5
v0.31.4
v0.31.3
v0.31.2
v0.31.1
v0.31.0
v0.30.7
v0.30.6
v0.30.5
v0.30.4
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.2
v0.23.1
v0.23.0
v0.22.0
v0.21.0
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.5
v0.18.4
v0.18.3
v0.18.2
v0.18.1
v0.18.0
v0.17.4
v0.17.3
v0.17.2
v0.17.1
v0.17.0
v0.16.3
v0.16.2
v0.16.1
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.1
v0.13.0
v0.12.2
v0.12.1
v0.12.0
v0.11.2
v0.11.1
v0.11.0
v0.10.0
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.2
v0.8.1
v0.8.0
v0.7.6
v0.7.5
v0.7.4
v0.7.3
0.7.2
v.0.7.1
v0.7.0
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.0
Labels
Clear labels
🎨 Design
📖 Docs Update
🐛 Bug
🐛 Bug
:cat2:🐈 Possible duplicate
💿 Database
☕ Open to discussion
💻 Front-End
🐕 Support
🚪 Authentication
🌍 Translations
🔌 API Task
🏭 Back-End
⛲ Upstream
🔨 Feature Request
🛠️ Enhancement
🛠️ Enhancement
🛠️ Enhancement
❤️ Happy feedback
🔒 Security
🔍 Pending Validation
💆 UX
📝 WYSIWYG Editor
🌔 Out of scope
🔩 API Request
:octocat: Admin/Meta
🖌️ View Customization
❓ Question
🚀 Priority
🛡️ Blocked
🚚 Export System
♿ A11y
🔧 Maintenance
> Markdown Editor
pull-request
Mirrored from GitHub Pull Request
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/BookStack#192
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @pinglanyue on GitHub (Oct 31, 2016).
In settings/roles page,can add 3 other permissions:
1.Lock : If locked,can't edit and delete (until unlock it).
2. Delete Forever and Delete:If DELETE a book,viewer can't see it,but didn't delete it from database,admin can recovery/reopen it.But if Delete Forever (only admin or settting roles ),the book will delete from database.(If a book was locked ,can't delete and "forever delete".)
3. Except the own and all permissions setting,can add a group setting.(Also should add a 'setting/group' page to set/control group.Or 'settings/roles' can have admin,editor,group,viewer by default setting )
@pinglanyue commented on GitHub (Nov 15, 2016):
Hi,@ssddanbrown .I use 0.13 and see new permission control.Consider current open issues about permissions:
#112
#299
#299
I have a idea about the permissions setting:
Now role setting
Use Group
Users page:
Individual: Own setting just here,user sign up have no role ,Individual role user can create book,and make a book private or public.
Group:later ~
Roles page:
Admin
Editor
GroupSuperAdmin
Group
Individual
Public
....(custom setting)
Group's role permissions(only Admin and GroupSuperAdmin can setting):
GroupAdmin
GroupEditor
GroupViewer(default)
no other role setting
Groups page:
User:Group=>N:N
(Admin/GroupSuperAdmin can create a group.One group only have one GroupSuperAdmin,but can have many GroupAdmin.GroupAdmin can't create book,but can manage all other thing.)
Example:
User1 create GroupA and GroupC。
Add user and setting user's pressions:UserA is GroupA's editor,can User3 is Group's admin.
Create a book/project named Book1,so this book can setting this permissions:Public(everyone can view,default setting)or Group(only selected group's user can see)。chapter and page 's permisson setting is inherit book permisson's setting.but also do this special thing:Book1 have Chapter1 and Chapter2,in Chapter permission setting,you can select by role or by group.ex:only want to GroupA manage Chapter1's content and GroupB manage Chapter2。
another case : Book2 is GroupA 's private book ,user can join GroupA to see it.Different group can make own project book.music group,movie group etc...if have a group setting,is onvenient on these scene.
Create a group is easy to manage content control.And create more and more custom role to control will became more and more diffculte.In some case ,Like javabook only who like java can see,
Also can make role control group,group control user.Admin is admingroup,editor is editorgroud,and single use alos can meaning only a user in a group...
@ssddanbrown commented on GitHub (Aug 4, 2018):
I'll be honest, I've never responded to this since I've never really understood the request here. After re-reading I still don't really understand. I appreciate the effort you've gone to here though.
This may even be solved with the good amount of permission system changes since this original request.
If you still require change in the permission system please open a new request with an example that's as simple as possible. Thanks.