#35959: Admin "Change password" Button Visible with Only "Can view user"
Permission
-------------------------------------+-------------------------------------
Reporter: Dev Namdev | Owner: Brock
| Smickley
Type: Bug | Status: assigned
Component: contrib.admin | Version: 5.1
Severity: Normal | Resolution:
Keywords: Permissions, Admin | Triage Stage: Accepted
Interface, Change Password, View |
User, Permission Bug |
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 1
-------------------------------------+-------------------------------------
Comment (by Brock Smickley):
Replying to [comment:5 Sarah Boyce]:
> This is actually quite similar to #33171
> I think maybe if the user has view only permission the password field
shouldn't be available (maybe updating `get_fieldsets`)
ok, I understand how to check the user's permissions from `get_fieldsets`
but then how do I omit the password field from there? I tried messing
around with the `exclude` option as well as the raw `fieldsets` tuple but
I couldn't figure anything out. is there an example of something like this
already in the codebase?
--
Ticket URL: <https://code.djangoproject.com/ticket/35959#comment:6>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion visit
https://groups.google.com/d/msgid/django-updates/010701939784f72f-69e776e7-5f49-4745-a880-5815097aab56-000000%40eu-central-1.amazonses.com.