Free RBAC (Community Edition)
How about RBAC / Fields permissions in USERS & PERMISSIONS PLUGIN?
marked this post as
Kai Doe: Thank you! Any planned release date?
Burak Aydik: it was released in v4.8.0 already
Derrick Mehaffy: ahh! My bad! Checking it right away!
Kai Doe: Thank you
marked this post as
Derrick Mehaffy: 💙💙💙
Derrick Mehaffy: 🎉🎉🎉
Also is it possible to have the same granularity we have for admin-users but fot the end-users. For instance being able for end-users to allow/ disallow access to some fields, or disable access/modification to other records owned by other users. In a word : having the same RBAC system for end-users as admin-users ?
Looking for this update soon, Thank Strapi team.
Hello, any updates on this? I also suffered the same issues but not only for Editor role, my Super Admin role even can't uncheck/check the boxes. Really weird.
I see the customization of the admin panel a high priority, because right now we have to hack the admin plugin in node_modules, which is painful.
The role permissions only controls the content-manager, in most time, we that content-manager interface is too rigid, as we develop things as plugin and create collections inside of it. Our html calls different api of single or collection types to pull over dropdown menu and use our own pixel-by-pixel requirements, and content-manager only suits basic need not all. Thus a customized role and permission based Admin Panel is very important.
From the questions being asked in your forum, stack-over-flow and discord, I see many people had the same concerns. We are seeing the momentum of headless CMS, and we would like to see your community version is robust in architecture.
Kevin Lee: For the admin customization you may want to comment and/or vote on this feature instead: https://feedback.strapi.io/feature-requests/p/customize-the-admin-dashboard-welcome-page-v4
Not sure if it is relevant but to me having RBAC is way more important then Internationalization. So putting Internationalization behind a paywall (or maybe along the lines of more then 2 languages) is way less intrusive then not being able to fully role control my application content.
Quote from Aurélien Georget from our forum a few months ago:
"Thank you all for your candid comments, it’s really appreciated! The limitation on the RBAC feature in the CE is a mandatory path for us, as some of you mentioned, we have to make money and pay the core team working full-time on Strapi.
From a user perspective, I do understand how frustrating it can be. We tried to be more generous than our competitors when we released the RBAC CE feature while also trying to give as much flexibility as necessary for most of the use cases we identified. Obviously, it doesn’t work all the time and the limitations might not make sense sometimes.
I really wanted to write this comment to share with you the future of RBAC. We invested a lot of time and effort in the v4, we don’t plan to release new paid features in the coming months, so nothing is going to change for the next 6 months. However, our end goal is to make RBAC 100% free and unlimited, hopefully, next year. We don’t have an ETA yet because we need to replace it with another one that would make sense for enterprises only.
In our vision of a modern CMS, RBAC + Internationalization should be default and free features for all. The Internationalization feature is already free and unlimited. Please allow us a bit more time to find the financial equation that would make what I just wrote possible. We want the same thing and empower millions of people to manage and share content"
See the full forum thread here: https://forum.strapi.io/t/rbac-role-based-access-control-feature-discussion/433/38
Derrick Mehaffy: For enterprise version, if you have this feature, please let me know. I am interested to learn. Also we deployed in AWS btw. I think it will not hurt your profit if you productize this feature into community edition sooner. What you can do is that you can offer a consulting team to help user build modules. I think the business model will expand even faster. The bigger adoption is, the more hooks you can have. Not killing customers in the cradle early time. Please make a html form on your site and let user submit the form to hire some consultant from your side. I will be interested.