Skip to content

Commit ea52a73

Browse files
markus-hentschjosephineSei
authored andcommitted
Update Standards/scs-0302-w1-domain-manager-implementation-notes.md
Co-authored-by: josephineSei <128813814+josephineSei@users.noreply.github.com> Signed-off-by: Markus Hentsch <129268441+markus-hentsch@users.noreply.github.com>
1 parent 9cc2d6d commit ea52a73

File tree

1 file changed

+0
-1
lines changed

1 file changed

+0
-1
lines changed

Standards/scs-0302-w1-domain-manager-implementation-notes.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,7 +133,6 @@ The only parts of the policy definitions below that may be changed are:
133133
"identity:revoke_grant": "(rule:domain_manager_grant and rule:is_domain_managed_role) or rule:base_revoke_grant or rule:admin_required"
134134
"identity:list_role_assignments": "(rule:is_domain_manager and token.domain.id:%(target.domain_id)s) or rule:base_list_role_assignments or rule:admin_required"
135135

136-
137136
# allow domain managers to manage groups within their domain
138137
"identity:list_groups": "(rule:is_domain_manager and token.domain.id:%(target.group.domain_id)s) or (role:reader and system_scope:all) or rule:base_list_groups or rule:admin_required"
139138
"identity:get_group": "(rule:is_domain_manager and token.domain.id:%(target.group.domain_id)s) or (role:reader and system_scope:all) or rule:base_get_group or rule:admin_required"

0 commit comments

Comments
 (0)