Skip to content

Enable content owner and deleter access to RecycleBin items without requiring ManageRecycleBin permission #4185

@rohnsha0

Description

@rohnsha0

Currently, users need the "Manage recycle bin" permission to access the RecycleBin. This issue proposes allowing additional access patterns so users can view and restore specific items without needing the full ManageRecycleBin permission:

  1. Content owners can access their own deleted items
  2. Users who deleted items can access items they deleted

Current Behavior

  • Users need Manage recycle bin permission to access RecycleBin
  • This permission can be granted to any role, but provides full RecycleBin access
  • Content creators and deleters cannot recover specific items without broad RecycleBin permissions

Proposed Solution

Create a new permission (e.g., "Access own recycled items") that allows users to:

  • View items they owned before deletion
  • View items they deleted
  • Restore these specific items
  • Cannot see other users' recycled items

Note: The existing "Manage recycle bin" permission will remain unchanged and continue to provide full access to all recycled items for users who have it.

see: #4176 (comment)

Metadata

Metadata

Assignees

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions