mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-08-16 20:49:00 -04:00
rather than allow admins to do everything specifically, we should only block them from things we conciously don't want them to do. This is "Don't let platform admins send letters from services they're not in". Everything else the platform admins can do. This is step one, adding a restrict_admin_usage flag, and setting that for those restricted endpoints around creating api keys, uploading CSVs and sending one-off messages. Also, this commit separates the two use cases for permissions: * user.has_permission for access control * user.has_permission_for_service for user info - this is used for showing checkboxes on the manage-users page for example With this, we can remove the admin_override flag from the permission decorator.
107 lines
3.7 KiB
HTML
107 lines
3.7 KiB
HTML
{% extends "withnav_template.html" %}
|
|
{% from "components/table.html" import list_table, row, field, hidden_field_heading %}
|
|
{% from "components/page-footer.html" import page_footer %}
|
|
{% from "components/tick-cross.html" import tick_cross %}
|
|
{% from "components/textbox.html" import textbox %}
|
|
|
|
{% set table_options = {
|
|
'field_headings': [
|
|
'Name', 'Send messages', 'Modify service', 'Access API keys', hidden_field_heading('Link to change')
|
|
],
|
|
'field_headings_visible': True,
|
|
'caption_visible': True
|
|
} %}
|
|
|
|
{% block service_page_title %}
|
|
Team members
|
|
{% endblock %}
|
|
|
|
{% block maincolumn_content %}
|
|
|
|
<div class="grid-row bottom-gutter">
|
|
<div class="column-two-thirds">
|
|
<h1 class="heading-large">
|
|
Team members
|
|
</h1>
|
|
</div>
|
|
{% if current_user.has_permissions('manage_service', admin_override=True) %}
|
|
<div class="column-one-third">
|
|
<a href="{{ url_for('.invite_user', service_id=current_service.id) }}" class="button align-with-heading">Invite team member</a>
|
|
</div>
|
|
{% endif %}
|
|
</div>
|
|
|
|
{% if show_search_box %}
|
|
<div data-module="autofocus">
|
|
<div class="live-search" data-module="live-search" data-targets=".user-list-item">
|
|
{{ textbox(
|
|
form.search,
|
|
width='1-1'
|
|
) }}
|
|
</div>
|
|
</div>
|
|
{% endif %}
|
|
|
|
<div class="user-list">
|
|
{% for user in users %}
|
|
<div class="user-list-item">
|
|
<h3>
|
|
{%- if user.name -%}
|
|
<span class="heading-small">{{ user.name }}</span> 
|
|
{%- endif -%}
|
|
<span class="hint">
|
|
{%- if user.status == 'pending' -%}
|
|
{{ user.email_address }} (invited)
|
|
{%- elif user.status == 'cancelled' -%}
|
|
{{ user.email_address }} (cancelled invite)
|
|
{%- elif user.id == current_user.id -%}
|
|
(you)
|
|
{% else %}
|
|
{{ user.email_address }}
|
|
{% endif %}
|
|
</span>
|
|
</h3>
|
|
<ul class="tick-cross-list">
|
|
<div class="tick-cross-list-permissions">
|
|
{{ tick_cross(
|
|
user.has_permission_for_service(current_service.id, 'send_messages'),
|
|
'Send messages'
|
|
) }}
|
|
{{ tick_cross(
|
|
user.has_permission_for_service(current_service.id, 'manage_templates'),
|
|
'Add and edit templates'
|
|
) }}
|
|
{{ tick_cross(
|
|
user.has_permission_for_service(current_service.id, 'manage_service'),
|
|
'Manage service'
|
|
) }}
|
|
{{ tick_cross(
|
|
user.has_permission_for_service(current_service.id, 'manage_api_keys'),
|
|
'Access API keys'
|
|
) }}
|
|
{% if 'email_auth' in current_service['permissions'] %}
|
|
<div class="tick-cross-list-hint">
|
|
{% if user.auth_type == 'sms_auth' %}
|
|
Signs in with a text message code
|
|
{% else %}
|
|
Signs in with an email link
|
|
{% endif %}
|
|
</div>
|
|
{% endif %}
|
|
</div>
|
|
{% if current_user.has_permissions('manage_service', admin_override=True) %}
|
|
<li class="tick-cross-list-edit-link">
|
|
{% if user.status == 'pending' %}
|
|
<a href="{{ url_for('.cancel_invited_user', service_id=current_service.id, invited_user_id=user.id)}}">Cancel invitation</a>
|
|
{% elif user.state == 'active' and current_user.id != user.id %}
|
|
<a href="{{ url_for('.edit_user_permissions', service_id=current_service.id, user_id=user.id)}}">Edit permissions</a>
|
|
{% endif %}
|
|
</li>
|
|
{% endif %}
|
|
</ul>
|
|
</div>
|
|
{% endfor %}
|
|
</div>
|
|
|
|
{% endblock %}
|