Administrator default role template starts with all rights GRANTED

FeatureInitializerService
Name
lúc 21:50 19 tháng 4, 2026 UTC
Tác giả
Kamo
Cam kết
38b9248

provisionMaxedOutMasterModel now populates the Administrator template with every RoleRightType set to GRANTED. The other three templates (Team Member, Member, DEFAULT) still materialize with zero rights (NOT_SPECIFIED for everything), matching the intended blank baseline for non-admin roles. Why GRANTED (not FORCE_GRANTED): at child-org creation time ChildOrgTemplateSeedingService copies non-force template values into the new org's OrgRoleRight rows, so a GRANTED admin template gives every new child org a ready-to-use admin role with full permissions that the owner can still edit. FORCE_GRANTED would lock rights at runtime and hide them from the security-roles editor, which we don't want for the admin template baseline.

Mọi thay đổi

Như những gì anh thấy vận chuyển?

Mỗi một bản cập nhật này đều được tự động cập nhật trong không gian làm việc của bạn. Bắt đầu tự do và xem nó lớn lên tuần này qua tuần khác.

Bắt đầu tự do mãi mãiXem truy cập