Skip to content

Collab user with read-write can delete the whole repository #896

@helmut72

Description

@helmut72

Describe the bug
Collab user with read-write can delete the whole repository

To Reproduce
Steps to reproduce the behavior:

  1. Create a new repository "test" as admin
  2. Create a new user "alice" as admin
  3. Add user "alice" to repo "test" with read-write permission
  4. Change to user "alice" and delete the repo
  5. works

Expected behavior
For my understanding, a user with read-write should be able to collab to a repo, but only a user with admin-access to a repo (or a global admin) should be able to delete the whole repository.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions