Skip to content
Discussion options

You must be logged in to vote

Hello,

I understand your point. As Eric mentioned the user object is at organisation level not at the domain, and both are linked with role assignment that is orthogonal.

My point is that seeing the users of your organisation is an intended feature for assignment management: both for setting the assignee or reading it, and seeing the users of your organisation is accordingly not a violation of any security principle: it's a pointer without any sensitive data leak.

That being said, that's the reason why I explained the relationship with multi tenancy management that we need to rework for pro and could benefit afterwards the CE.

Hope that makes it clearer :)

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by ab-smith
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
question Further information is requested
3 participants
Converted from issue

This discussion was converted from issue #1777 on May 02, 2025 11:20.