Hey! I just came across this on my first website, where I restrict user access using the built-in Bricks functions. I disabled everything initially (except the post types that can be edited), but users can still access the command palette with all the options: Classes, variables, and fonts. That shouldn’t be possible. That’s where they can cause a lot of damage. Have I done something wrong, or is this how it’s supposed to be for the time being?
I have deactivated all rights and only activated “Edit pages with Bricks” - so the user can’t actually do anything except open the builder.
In my tests, I was unable to delete fonts, classes or variables. With classes and variables it seems as if it is possible, but they are there again after a builder reload. An error message appears for the fonts. However, I was able to delete icons from my custom icon set - that is the only really critical problem.
However, it is certainly to be expected that you can’t reach the “manager” in the first place if you don’t have any rights. And a separate setting for the command palette would certainly not be bad either