Skip to content

docs - pro user groups info #12127

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Apr 1, 2025
Merged

Conversation

paulOsinski
Copy link
Contributor

Adds additional context on working with User Groups in the Beta UI.

@github-actions github-actions bot added the docs label Mar 28, 2025
Copy link

dryrunsecurity bot commented Mar 28, 2025

DryRun Security Summary

DefectDojo Pro documentation updates clarify user group management and configuration permissions, emphasizing access control, granular permission management, and safeguards against unintended privilege escalation.

Expand for full summary

Summary: Documentation updates for DefectDojo Pro focusing on user group management and configuration permissions, providing enhanced guidance for user and group permission controls.

Security Findings:
• Access Control Considerations

  • Only Superusers can create and modify User Groups
  • Individual user roles can supersede group roles
  • Configuration permissions are carefully controlled

• Permission Management Observations

  • Granular permission management interface
  • Confirmation step before updating permissions prevents unintended changes
  • Grouped permissions help prevent accidental over-privileging of users

No direct security vulnerabilities were detected in these documentation updates.

View PR in the DryRun Dashboard.

@Maffooch Maffooch added this to the 2.45.0 milestone Mar 31, 2025
@Maffooch Maffooch changed the base branch from bugfix to master March 31, 2025 19:58
Copy link
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

@Maffooch Maffooch merged commit 56325f7 into DefectDojo:master Apr 1, 2025
77 of 78 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants