Originally created by @florian-bellencontre on GitHub (Apr 19, 2023).
Subject of the issue
The "Manager" cannot edit the users of a group in an organization. The description of the role manager says "... and manage access in assigned collections" but yet it has the same rights as a normal user with the addition of the "Organizations" category.
Deployment environment
Diag:
vaultwarden version: 1.28.1
Install method: Installation from releases and with a compilation
Clients used: Browser (firefox, chrome)
Reverse proxy and version: haproxy
Steps to reproduce
Create an organization
Create a group
Assign a user to the organization and group
Promote to manager rank
Expected behaviour
Display groups and user assignments to groups like this:
Actual behaviour
The manager can't manage the users of the groups:
Originally created by @florian-bellencontre on GitHub (Apr 19, 2023).
### Subject of the issue
The "Manager" cannot edit the users of a group in an organization. The description of the role manager says "... and manage access in assigned collections" but yet it has the same rights as a normal user with the addition of the "Organizations" category.
### Deployment environment
Diag:

* vaultwarden version: 1.28.1
* Install method: Installation from releases and with a compilation
* Clients used: Browser (firefox, chrome)
* Reverse proxy and version: haproxy
### Steps to reproduce
1. Create an organization
2. Create a group
3. Assign a user to the organization and group
4. Promote to manager rank
### Expected behaviour
Display groups and user assignments to groups like this:

### Actual behaviour
The manager can't manage the users of the groups:

A manager will not be able to edit users of a group. If they have access to a collection they should be able to edit who (or which group) has access to that collection. Which works if a manager has been given direct access to an collection.
However it seems like this does not work at the moment for access via groups which is why the groups feature is still considered experimental and not enabled by default.
@stefan0xC commented on GitHub (Apr 19, 2023):
A manager will not be able to edit users of a group. If they have access to a collection they should be able to edit who (or which group) has access to that collection. Which works if a manager has been given direct access to an collection.
However it seems like this does not work at the moment for access via groups which is why the groups feature is still considered experimental and not enabled by default.
I just looked and indeed a manager user can add a group into a collection so no worries on this side.
I see that it is not a Vaultwarden problem. I'm going to look for a feature request or an improvement on Biwarden side.
Thank you very much for your feedback and you can close this issue.
@Floflobel commented on GitHub (Apr 19, 2023):
I just looked and indeed a manager user can add a group into a collection so no worries on this side.
I see that it is not a Vaultwarden problem. I'm going to look for a feature request or an improvement on Biwarden side.
Thank you very much for your feedback and you can close this issue.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @florian-bellencontre on GitHub (Apr 19, 2023).
Subject of the issue
The "Manager" cannot edit the users of a group in an organization. The description of the role manager says "... and manage access in assigned collections" but yet it has the same rights as a normal user with the addition of the "Organizations" category.
Deployment environment
Diag:

Steps to reproduce
Expected behaviour
Display groups and user assignments to groups like this:

Actual behaviour
The manager can't manage the users of the groups:

@stefan0xC commented on GitHub (Apr 19, 2023):
A manager will not be able to edit users of a group. If they have access to a collection they should be able to edit who (or which group) has access to that collection. Which works if a manager has been given direct access to an collection.
However it seems like this does not work at the moment for access via groups which is why the groups feature is still considered experimental and not enabled by default.
@Floflobel commented on GitHub (Apr 19, 2023):
I just looked and indeed a manager user can add a group into a collection so no worries on this side.
I see that it is not a Vaultwarden problem. I'm going to look for a feature request or an improvement on Biwarden side.
Thank you very much for your feedback and you can close this issue.