Description
When an administrator creates a collective in the Collectives app and assigns a user as a moderator, the moderator cannot manage the collective's members or groups in the Collectives app, which is the expected behavior.
However, the same collective is also available in the Contacts app, where the moderator can add or remove members and groups.
This results in inconsistent permission handling between the two apps and allows the moderator to perform actions that are not permitted in Collectives.
Steps to reproduce
Log in as an administrator.
Create a new collective in the Collectives app.
Assign a user as the collective moderator.
Log in as the moderator.
Verify that the moderator cannot add or remove members or groups in the Collectives app.
Open the Contacts app.
Open the same collective.
Notice that the moderator can add or remove members and groups.
Expected behavior
A moderator should not be able to manage the collective's members or groups in either Collectives or Contacts. Permission enforcement should be consistent across both applications.
Actual behavior
The moderator cannot manage members in Collectives, but can add or remove members and groups in Contacts, bypassing the permission restrictions defined in Collectives.
Description
When an administrator creates a collective in the Collectives app and assigns a user as a moderator, the moderator cannot manage the collective's members or groups in the Collectives app, which is the expected behavior.
However, the same collective is also available in the Contacts app, where the moderator can add or remove members and groups.
This results in inconsistent permission handling between the two apps and allows the moderator to perform actions that are not permitted in Collectives.
Steps to reproduce
Log in as an administrator.
Create a new collective in the Collectives app.
Assign a user as the collective moderator.
Log in as the moderator.
Verify that the moderator cannot add or remove members or groups in the Collectives app.
Open the Contacts app.
Open the same collective.
Notice that the moderator can add or remove members and groups.
Expected behavior
A moderator should not be able to manage the collective's members or groups in either Collectives or Contacts. Permission enforcement should be consistent across both applications.
Actual behavior
The moderator cannot manage members in Collectives, but can add or remove members and groups in Contacts, bypassing the permission restrictions defined in Collectives.