Let a person see which plugins are running for them, and who decided #96

Closed
opened 2026-09-07 15:19:04 +00:00 by tiagoagueda · 0 comments
Owner

Observation

admin plugin page:
repos: internal (cannot be disable), oficial (can be enable/disable and customized, if it
is not on the env, like smtp), multiple repos that can be enable/disable/customized

plugins kinds: internal (shipped with postulo), oficial plugin (downloaded from official
repo, or thru a zip) custom plugin (downloaded from custom repo, or thru a zip)
all plugins can be enable and disable but a admin can impose enable/disable of a plugin on
any user

user-plugin:
can see what current plugins (either kind) are enable in their session

Last of four. Depends on the policy issue, which is what gives this page anything to say.

What exists

Settings -> Connections lists the connections a person has made: a label, a plugin, a
switch, and whether the last attempt worked. That answers "what have I set up".

It does not answer "what is running for me". Sources -- the parsers that read a posting off a
page -- need no connection and appear nowhere. Nor does anything say why a plugin is
available: shipped, installed by the operator, chosen by the person, or decided for them.

What this asks for

One page, listing every plugin this account can use, and for each: whether it is on, and
why.

Why What the person can do
Shipped with Postulo Nothing; it is part of the application
Installed here, on by default Turn it off for themselves
Turned on by them Turn it off
Decided by an administrator Nothing, and the page says so

The last row is the one that matters, and it is why this issue exists separately from a
tidy-up of the connections page. A permission an administrator holds over somebody's account
should be visible to that person from their own settings, without asking anybody. If the
policy issue lands and this one does not, an account can be quietly configured by somebody
else -- which is precisely the arrangement worth avoiding.

A note on wording

The request says "enabled in their session". Plugin state is per account rather than per
session: signing in elsewhere does not change it, and it survives signing out. Unless
something session-scoped is actually wanted -- a plugin on for this browser only, which
sounds more like a debugging aid than a feature -- the page should say "for your account" and
mean it. Flagged because a page that says session while meaning account teaches people
something untrue about where their settings live.

Scope

  • A settings section listing plugins by kind, with state and reason.
  • What the person may change, they may change from there; what they may not is shown as not
    theirs to change, with who decided it.
  • Reachable with scripts off and readable by a screen reader, like everything else.
  • Tests: each reason renders; a plugin decided by an administrator offers no control; one
    person's page never shows another's state.

Classification

Enhancement, interface.

## Observation > admin plugin page: > repos: internal (cannot be disable), oficial (can be enable/disable and customized, if it > is not on the env, like smtp), multiple repos that can be enable/disable/customized > > plugins kinds: internal (shipped with postulo), oficial plugin (downloaded from official > repo, or thru a zip) custom plugin (downloaded from custom repo, or thru a zip) > all plugins can be enable and disable but a admin can impose enable/disable of a plugin on > any user > > user-plugin: > can see what current plugins (either kind) are enable in their session Last of four. Depends on the policy issue, which is what gives this page anything to say. ## What exists *Settings -> Connections* lists the connections a person has made: a label, a plugin, a switch, and whether the last attempt worked. That answers "what have I set up". It does not answer "what is running for me". Sources -- the parsers that read a posting off a page -- need no connection and appear nowhere. Nor does anything say why a plugin is available: shipped, installed by the operator, chosen by the person, or decided for them. ## What this asks for One page, listing every plugin this account can use, and for each: whether it is on, and **why**. | Why | What the person can do | | --- | --- | | Shipped with Postulo | Nothing; it is part of the application | | Installed here, on by default | Turn it off for themselves | | Turned on by them | Turn it off | | Decided by an administrator | Nothing, and the page says so | The last row is the one that matters, and it is why this issue exists separately from a tidy-up of the connections page. A permission an administrator holds over somebody's account should be visible to that person from their own settings, without asking anybody. If the policy issue lands and this one does not, an account can be quietly configured by somebody else -- which is precisely the arrangement worth avoiding. ## A note on wording The request says *"enabled in their session"*. Plugin state is per account rather than per session: signing in elsewhere does not change it, and it survives signing out. Unless something session-scoped is actually wanted -- a plugin on for this browser only, which sounds more like a debugging aid than a feature -- the page should say "for your account" and mean it. Flagged because a page that says *session* while meaning *account* teaches people something untrue about where their settings live. ## Scope - A settings section listing plugins by kind, with state and reason. - What the person may change, they may change from there; what they may not is shown as not theirs to change, with who decided it. - Reachable with scripts off and readable by a screen reader, like everything else. - Tests: each reason renders; a plugin decided by an administrator offers no control; one person's page never shows another's state. ## Classification Enhancement, interface.
tiagoagueda added this to the 0.3.0 milestone 2026-09-07 15:19:04 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Postulo/postulo#96
No description provided.