Conversation
Enable ACLs before assigning team ownership and grant the owning circle ACL management rights. Keep the reserved .system directory accessible in team folders despite restrictive ACL rules, reject ACL changes for that path, and migrate existing team folders to ACL-enabled. Add coverage for team-folder creation and .system ACL handling. Co-authored-by: Copilot <copilot@github.com> GPT-5.6 Terra Signed-off-by: Stefan Lender <Stefan.Lender@dataport.de>
hefftich
force-pushed
the
feature/reenabling_acl_for_teamfolders
branch
from
September 28, 2026 07:17
d1f85df to
656cd7f
Compare
marcoambrosini
requested changes
Sep 28, 2026
marcoambrosini
left a comment
Member
There was a problem hiding this comment.
Blocking for now as it needs further discussion, as per our meeting today
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR relates to #2893 in circles.
For several organizations, ACL's are really a key feature for Team folders. We should re-enable this for 35.0.1.
We disabled it to keep things simpler, but it would mean quite some orgs can't use 35's new Team folder concept. I would thus suggest simply turning it on again.
NOTE, quoting @artonge
Also, I can see an issue coming with ACL + .system folder in which we store the Teams data, which means, everybody should be able to read and write to it.
So we have to solve that first. Let's see if that is doable for .1
Enable ACLs before assigning team ownership and grant the owning circle ACL management rights.
Keep the reserved .system directory accessible in team folders despite restrictive ACL rules, reject ACL changes for that path, and migrate existing team folders to ACL-enabled.
Add coverage for team-folder creation and .system ACL handling.
π€ AI (if applicable)