@@ -340,10 +340,10 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
340
340
Identifier : RoleUserAdmin (),
341
341
DisplayName : "User Admin" ,
342
342
Site : Permissions (map [string ][]policy.Action {
343
- ResourceAssignRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead , policy . ActionUpdate },
343
+ ResourceAssignRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead },
344
344
// Need organization assign as well to create users. At present, creating a user
345
345
// will always assign them to some organization.
346
- ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead , policy . ActionUpdate },
346
+ ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead },
347
347
ResourceUser .Type : {
348
348
policy .ActionCreate , policy .ActionRead , policy .ActionUpdate , policy .ActionDelete ,
349
349
policy .ActionUpdatePersonal , policy .ActionReadPersonal ,
@@ -458,7 +458,7 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
458
458
Org : map [string ][]Permission {
459
459
organizationID .String (): Permissions (map [string ][]policy.Action {
460
460
// Assign, remove, and read roles in the organization.
461
- ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead , policy . ActionUpdate },
461
+ ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead },
462
462
ResourceOrganizationMember .Type : {policy .ActionCreate , policy .ActionRead , policy .ActionUpdate , policy .ActionDelete },
463
463
ResourceGroup .Type : ResourceGroup .AvailableActions (),
464
464
}),
0 commit comments