generated from cisagov/ScubaGear
-
Notifications
You must be signed in to change notification settings - Fork 45
Open
Labels
baseline-documentIssues relating to the text in the baseline documents themselvesIssues relating to the text in the baseline documents themselvesenhancement
Milestone
Description
Prerequisites
- This issue has an informative and human-readable title.
💡 Summary
GWS.CLASSROOM.1.1 and 1.2 may be too strict.
Motivation and context
The policies currently read as:
- Who can join classes in your domain SHALL be set to Users in your domain only.
- Which classes users in your domain can join SHALL be set to Classes in your domain only.
This feels unnecessarily strict. For example, both settings have an "allowlisted domains" option. I don't see why that shouldn't be allowed.
Implementation notes
Potential re-wordings:
- Who can join classes in your domain SHALL be restricted to users in your domain or allowlisted domains.
- Which classes users in your domain can join SHALL be restricted to classes in your domain or allowlisted domains.
Note that this update will necessitate a ScubaGoggles code change.
Acceptance criteria
- Determine if baseline change is needed (yes)
- Update Classroom baseline
- Update Classroom Rego code for change
Metadata
Metadata
Assignees
Labels
baseline-documentIssues relating to the text in the baseline documents themselvesIssues relating to the text in the baseline documents themselvesenhancement