J3 Issue ?
avatar Open2logic
Open2logic
26 Sep 2018

Steps to reproduce the issue

Example (in the admin)
We add 2 user groups with Access Level for work in the backend (adminitration)
Group1 & Group 2.

We add modules for the admin with Access Group 1
And add anothers modules for the admin with Acces Group 2

Also we add one menú admin with Access Group 1
And we add another menu admin with Access Gorup 2

All the workers in Group 1 only see the menu and the modules with Access Group 1 - OK
All the workers in Group 2 only see the menu and the modules with Access Group 1 - OK

BUT ..... we go to the USERS / MANAGE

And the webmaster with access Group 1 can see the private data of all the users that are not of his group

Expected result

Go to Users / Manage:
Only show users of the same acces level

Actual result

Any administrator, regardless of their level of access can see all the data of registered users.

This is not functional for school websites, classified ads websites, business websites with departments that work on the web, etc.

System information (as much as possible)

Joomla 3.8.12

Additional comments

IDEA
In Users/ manage / Options / Permissions
Add a new fuction : ONLY SEE USERS OF THE SAME GROUP

add users-joomla

avatar Open2logic Open2logic - open - 26 Sep 2018
avatar joomla-cms-bot joomla-cms-bot - change - 26 Sep 2018
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 26 Sep 2018
avatar Open2logic Open2logic - change - 26 Sep 2018
The description was changed
avatar Open2logic Open2logic - edited - 26 Sep 2018
avatar Open2logic Open2logic - change - 26 Sep 2018
The description was changed
avatar Open2logic Open2logic - edited - 26 Sep 2018
avatar franz-wohlkoenig franz-wohlkoenig - change - 26 Sep 2018
Category com_csp
avatar Open2logic Open2logic - change - 26 Sep 2018
Title
RGPD (European law on data protection) in USERS / MAN
European law on data protection) in USERS / MANAGER
avatar Open2logic Open2logic - edited - 26 Sep 2018
avatar franz-wohlkoenig franz-wohlkoenig - change - 26 Sep 2018
Title
European law on data protection) in USERS / MANAGER
RGPD (European law on data protection) in USERS / MAN
avatar joomla-cms-bot joomla-cms-bot - edited - 26 Sep 2018
avatar franz-wohlkoenig franz-wohlkoenig - change - 26 Sep 2018
Category com_csp ACL Administration com_csp com_users
avatar brianteeman
brianteeman - comment - 26 Sep 2018

There is nothing in the law about this.

The users component is not designed to limit access to specific groups. If you dont want people to see it then dont give their group access to the component

avatar brianteeman brianteeman - change - 26 Sep 2018
Labels Added: J3 Issue
avatar brianteeman brianteeman - labeled - 26 Sep 2018
avatar franz-wohlkoenig franz-wohlkoenig - change - 26 Sep 2018
Status New Information Required
avatar Open2logic
Open2logic - comment - 28 Sep 2018

The lawyers say that when a cms show all registered users to all webmasters, 2 things are required:

  1. Let the company comply with RGPD and
  2. All webmasters must sign a privacy policy document with the company.

This is quite correct, but, and if they are not webmasters who access the users.
A website of a school, where teachers have access to registered students.
A sports tournament website where coaches have access to registered youth teams
A holiday camp website where monitors can see registered children
Etc, etc, etc.

Ok, maybe it's not an issue but this could be in Joomla 4 and go up a new level, simply allowing an option to show only users of the same group,
Las posibilidades de nuevos escenarios para otro tipo de web que ahora com_users no puede abordar y The possibilities of new scenarios for another type of web that now com_users can not make and third-party com-ponents are required.

I think it's a great best, expressed otherwise.

Why a registered user can see the name and email of a user of a higher group but can not edit it?
That user can not edit it and should not see it

Attached capture of registered user who needs to have access to the administration and com_users and can see the data of users of higher groups.

datos

avatar brianteeman
brianteeman - comment - 28 Sep 2018

All of what you say can be achieved without using the user manager. There are much better ways to deal with that level of user management.

avatar brianteeman
brianteeman - comment - 28 Sep 2018

In fact for the examples you describe I wouldn't recommend user manager irrelevant of gdpr

avatar Open2logic
Open2logic - comment - 28 Sep 2018

Perfect, thanks Brian, so I do not know how to show users from the same group as the webmaster.
If you do not think it would be good to implement it in Joomla 4, you can close the proposal. Thanks again

avatar Open2logic
Open2logic - comment - 28 Sep 2018

But if I see it important that a user who must access the com_users not see the data of super-users or users of higher levels

avatar infograf768
infograf768 - comment - 29 Sep 2018

In fact, if I do not mistake, what you are asking for is the implementation of specific permissions for User Groups. I.e. define which groups(s) a specific group of users can see in the User Manager (not only Upper levels btw).

I guess this would be possible. Requires a volunteer with enough coding skills to implement.
This is indeed not specifically related to RGDP.

avatar alikon
alikon - comment - 29 Sep 2018

gdpr/rgdpr or whatever random mix of these letter ...
.. me still looking for the source of the TRUE (with no luck), suddenly everything can be a gdpr/rgdpr requirement/issue ..... #grrr

avatar infograf768
infograf768 - comment - 29 Sep 2018

LOL
GDPR is the English acronym:
General Data Protection Regulation
https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-does-general-data-protection-regulation-gdpr-govern_en

in French it is
Règlement général sur la protection des données,
therefore RGPD
https://ec.europa.eu/info/law/law-topic/data-protection/reform/what-does-general-data-protection-regulation-gdpr-govern_fr

and in Italian
also RGPD
as it is
Regolamento generale sulla protezione dei dati

avatar Open2logic
Open2logic - comment - 29 Sep 2018

Are two different topics:

  1. About RGPD: Do not show the data of all users to all developers who can access com_users if they have not signed a privacy document

  2. About select groups: Being able to assign which groups can be displayed would be a great improvement for Joomla 4 and allow to create other websites that now require a third party extension.

But with the second proposal you can solve the first, limiting what users can see with access to com_users.

avatar franz-wohlkoenig franz-wohlkoenig - change - 5 Mar 2019
Status Information Required Discussion
avatar joomla-cms-bot joomla-cms-bot - change - 4 Jul 2019
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2019-07-04 12:30:58
Closed_By joomla-cms-bot
avatar alikon alikon - change - 4 Jul 2019
Closed_Date 2019-07-04 12:30:58 2019-07-04 12:30:59
Closed_By joomla-cms-bot alikon
avatar joomla-cms-bot joomla-cms-bot - close - 4 Jul 2019
avatar joomla-cms-bot
joomla-cms-bot - comment - 4 Jul 2019

Set to "closed" on behalf of @alikon by The JTracker Application at issues.joomla.org/joomla-cms/22371

avatar alikon
alikon - comment - 4 Jul 2019

3.x is feature freeze
if needed please open a new issue for 4.x


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/22371.

Add a Comment

Login with GitHub to post a comment