@@ -342,10 +342,10 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
342
342
Identifier : RoleUserAdmin (),
343
343
DisplayName : "User Admin" ,
344
344
Site : Permissions (map [string ][]policy.Action {
345
- ResourceAssignRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead , policy . ActionUpdate },
345
+ ResourceAssignRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead },
346
346
// Need organization assign as well to create users. At present, creating a user
347
347
// will always assign them to some organization.
348
- ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead , policy . ActionUpdate },
348
+ ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead },
349
349
ResourceUser .Type : {
350
350
policy .ActionCreate , policy .ActionRead , policy .ActionUpdate , policy .ActionDelete ,
351
351
policy .ActionUpdatePersonal , policy .ActionReadPersonal ,
@@ -461,7 +461,7 @@ func ReloadBuiltinRoles(opts *RoleOptions) {
461
461
Org : map [string ][]Permission {
462
462
organizationID .String (): Permissions (map [string ][]policy.Action {
463
463
// Assign, remove, and read roles in the organization.
464
- ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead , policy . ActionUpdate },
464
+ ResourceAssignOrgRole .Type : {policy .ActionAssign , policy .ActionDelete , policy .ActionRead },
465
465
ResourceOrganizationMember .Type : {policy .ActionCreate , policy .ActionRead , policy .ActionUpdate , policy .ActionDelete },
466
466
ResourceGroup .Type : ResourceGroup .AvailableActions (),
467
467
ResourceGroupMember .Type : ResourceGroupMember .AvailableActions (),
0 commit comments