#1510 tag permission vs un/tagBuildBypass
Closed: Fixed by tkopecek. Opened by tkopecek.

It would make sense, that these calls can be used with 'tag' permission instead of 'admin' after #1453


More general question is how to deal with --force for tagging operations. should be tag sufficient here, or do we still want to have admin for that?

Metadata Update from @tkopecek:
- Custom field Size adjusted to None

Metadata Update from @tkopecek:
- Issue tagged with: discussion, feature

tagBuildBypass skips the policy check, among other things, similar to --force for regular tagging.

I guess it's a question of how powerful we want the tag permission to be. Do we need multiple levels here?

Usecase is that all relengs would still need the 'admin' permission if 'tag/target' permissions are not enough for normal tasks. In such case only some services could benefit of these. On the other hand, services shouldn't have --force available. (Ugly idea is to have tag and tag-admin)

Metadata Update from @tkopecek:
- Issue set to the milestone: 1.19

What is the motivation for tagBuildBypass skipping the policy check? I thought tagBuildBypass was purely a performance optimizations where thousands of tagging operations could happen quickly without creating tasks for each.

@dgregor It is e.g. used by koji-gc which has its own policies.

PR #1685

Commit 281a664a fixes this issue

Commit fb82f048 fixes this issue

Metadata Update from @dgregor:
- Issue assigned to breilly

Metadata Update from @jcupova:
- Issue tagged with: testing-done

This issue has been migrated to Fedora Forge:
https://forge.fedoraproject.org/koji/koji/issues/1510

Please continue any further discussion there.

Metadata
Related Pull Requests