Updates to policies #589
Labels
Epic #45: Applicant view applications permission
Applicant view applications by permission
Epic #60: Reviewer view applications by permission
Reviewer view applications by permission
Feature: refactor
Code needs refactoring/optimising
Milestone
After discussion with @andreievg:
Top priority
user
andorganisation
tables so that there is a policy to restrict by org (only see users in own orgs), restrict by user (only see orgs users belong to), and a non-restricted policy (for senior staff to see all users/orgs)Next priority
For safety
Regarding new Outcomes, it was agreed that ultimately a full row-level solution would be desirable, building the methodology to create appropriate policies on the fly for new tables is not trivial and would be tricky to customise for multiple outcome layouts, so we will create a "filtering" option also on OutcomeDisplay configs to handle this through the API -- and Outcomes will only be accessed outside the server via the API -- see #590
The text was updated successfully, but these errors were encountered: