On Fri 25 Nov 2016 at 15:48:31 +0000, Brian Potkin wrote: > On Fri 25 Nov 2016 at 13:35:26 +0100, Narcis Garcia wrote: > > > In my opinion, desktop printers tools should trigger actions as same > > desktop user account. > > lpadmin group ever should be allowed on all related features. > > If root is added to SystemGroup what happens to the "fine-grained > privileges" aspect of cups-pk-helper? Does it have any effect?
To continue this train of thought and hopefully add something of substance I added root to SystemGroup in cups-files and restarted cups. A queue was paused with cupsdisable. From g-c-c it was possible to cancel the job without unlocking the printing dialog. After unlocking I was able add/delete printers, start/stop a printer set a default printer and apparently change queue options. Sabotage of fine-grained privileges by cups might not go down well. :) -- Brian.
