[resolved] Stream menu visible for custom user roles (2 posts)

  1. Richard van Denderen
    Posted 2 years ago #

    Stream menu is always visible, and so are the settings for custom user role's.
    The stream it self is hidden though but because users can access the settings. It's also possible for them to change them and allow them self to get access to the stream.


  2. Frankie Jarrett
    Plugin Author

    Posted 1 year ago #

    Hi Richard! Thanks for your comment.

    Stream has two access capabilities, viewing Stream and changing Stream settings. You can see these capabilities in the Stream codebase here.

    Viewing records requires the view_stream capability to be assigned to a role.

    Stream Settings on the other hand can be changed by any role that has been granted the manage_options capability. This is a high-level generic capability that is built into WP and reserved for Administrators to be able to change settings. It is used most commonly by other plugins for the same purpose.

    If you would like certain roles to not be able to change Stream Settings, then that capability should be removed from their role.

    In the future we'd like to allow this value to be filterable so it can be changed by developers to be anything they desire.

Topic Closed

This topic has been closed to new replies.

About this Plugin

  • Stream
  • Frequently Asked Questions
  • Support Threads
  • Reviews

About this Topic