Feature #33071

Prevent accidental deletion of contents with sudo mode

Added by Go MAEDA 4 months ago. Updated 4 months ago.

Status:ReopenedStart date:
Priority:NormalDue date:
Assignee:Go MAEDA% Done:

0%

Category:UI
Target version:4.2.0
Resolution:Fixed

Description

The attached patch adds protection against deletion of contents such as issues, wiki pages, and attachments by expanding operations covered by sudo mode that has been added in Redmine 3.1 (#19851).

Users sometimes mistakenly delete contents like issues. I think it is because deleting contents is so easy if they have appropriate permissions.

I think such accidents can be reduced with sudo mode. If sudo mode guards deletion of contents as well by requiring re-entering a password, users can have an opportunity to reconsider the operation.

Step 1: the user see "Are you sure?" dialog after clicking "Delete" button. Not a few users press OK without thinking.

Step 2: if sudo mode is enabled in configuration.yml and the attached patch is applied, Redmine requires user to re-enter their password before performing deletion. The user may notice that they are doing a daingerous operation.

0001-Require-sudo-mode-for-deleting-contents.patch Magnifier (6.61 KB) Go MAEDA, 2020-03-01 10:03

deletion-step-1@2x.png (78.5 KB) Go MAEDA, 2020-03-01 10:09

deletion-step-2@2x.png (28.4 KB) Go MAEDA, 2020-03-01 10:09

0001-Require-sudo-mode-for-actions-to-delete-contents.patch Magnifier (8.08 KB) Go MAEDA, 2020-03-07 08:11


Related issues

Related to Redmine - Feature #2893: Add a view to confirm issue deletion Reopened 2009-03-04

Associated revisions

Revision 19569
Added by Go MAEDA 4 months ago

Require sudo mode for actions to delete contents (#33071).

Patch by Go MAEDA.

Revision 19579
Added by Go MAEDA 4 months ago

Reverts r19569 (#33071).

404 error after deleting an attachment.

History

#1 Updated by Go MAEDA 4 months ago

  • Related to Feature #2893: Add a view to confirm issue deletion added

#2 Updated by Go MAEDA 4 months ago

Added tests to the patch.

#3 Updated by Go MAEDA 4 months ago

  • Target version changed from Candidate for next major release to 4.2.0

Setting the target version to 4.2.0.

#4 Updated by Marius BALTEANU 4 months ago

The instances without sudo mode enabled won't be able to use this feature, right?

#5 Updated by Go MAEDA 4 months ago

Marius BALTEANU wrote:

The instances without sudo mode enabled won't be able to use this feature, right?

Yes, that is right. The patch extends sudo mode, so there is no change in behavior on Redmine instances without sudo mode enabled.

#6 Updated by Go MAEDA 4 months ago

  • Status changed from New to Closed
  • Assignee set to Go MAEDA
  • Resolution set to Fixed

Committed the patch.

#7 Updated by Marius BALTEANU 4 months ago

Go MAEDA wrote:

Committed the patch.

Even if the patch is already committed, I think it's too much to require the password for delete actions and to have this feature only for the instances with sudo mode enabled. I think making the delete action harder, it's good idea. What I saw in the last period in many web applications (starting from cloud platforms to Github, Gitlab) it's a custom confirmation modal that requires a manual input like "yes" from the user in order to continue the action.

Also, in some cases like issue page, the delete button it's easily mismatch with the delete button from comment and what we can do there is to hide the button under actions dropdown.

I'm reopening this to take more feedback from the users, I don't think that such a change should go so quickly in the next release.

#8 Updated by Marius BALTEANU 4 months ago

  • Status changed from Closed to Reopened

#9 Updated by Go MAEDA 4 months ago

It will be nice if an alternative implementation is introduced before the release of 4.2.0.

But I believe that a mechanism to guard contents against such accidents is indispensable and the sudo mode works well until another mechanism is implemented. I will happily replace this if another patch is suggested.

Before that, I think the sudo mode is a good workaround. Probably not many instances enable sudo mode, the instances influenced by this extended sudo mode are limited. So, most users Redmine can delete contents as usual even after their instance is upgraded.

Also available in: Atom PDF