Uploaded image for project: 'Sakai'
  1. Sakai
  2. SAK-32542

Allow non-admins to use /direct/user more fully.



    • Type: Feature Request
    • Status: RESOLVED
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: 11.3
    • Fix Version/s: 12.0
    • Component/s: Entity Broker
    • Labels:


      At the moment a user can use /direct/user to find out information about themselves but they can't use it to find our information about other users. It would be useful if users could use /direct/user to find out information about other users and to search for them.

      Sakai has a complex permissions model around seeing user information that isn't implemented by a service but is does it in an adhoc manner by the tools in each site. Ideally we could have /direct/user work without the context of a site but this might be a bridge too far.

      The profile tool currently allows anyone who has access to it (normally through their My Workspace) to search for other users by ID, name, email (and interests). However if a deployment doesn't want this they typically would just remote the profile tool rather than changing any permissions.

      If the user is a maintainer in a site and can add new members to that site then they have the ability to search for users using the Site Info tool. This allows searching by IDs or email.

      If the user is just a member of a site and the roster tool is present then they can see anyone in that site's details unless that user has chosen to hide themselves using the privacy feature of the preferences tool.

        Gliffy Diagrams





                • Assignee:
                  buckett Matthew Buckett
                  buckett Matthew Buckett
                • Votes:
                  0 Vote for this issue
                  1 Start watching this issue


                  • Created:

                    Git Integration