# Migration to @forestadmin/agent - permission problems with disassociate relationship

**URL:** <https://community.forestadmin.com/t/migration-to-forestadmin-agent-permission-problems-with-disassociate-relationship/7510>\
**Category:** Help me!\
**Created:** [October 3, 2024, 2:15pm UTC](https://community.forestadmin.com/t/migration-to-forestadmin-agent-permission-problems-with-disassociate-relationship/7510 "2024-10-03T14:15:54Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![morganperre](https://dub1.discourse-cdn.com/flex013/user_avatar/community.forestadmin.com/morganperre/32/1296_2.png) [@morganperre](https://community.forestadmin.com/u/morganperre)\
**Post date:** [October 8, 2024, 9:06am UTC](https://community.forestadmin.com/t/migration-to-forestadmin-agent-permission-problems-with-disassociate-relationship/7510/3 "2024-10-08T09:06:28Z")

</div>

Hello @Matteo,

Sorry for the late response we were in an event last week and your ticket has been lost in the way…

It reminds me this thread about dissociate… and the fact that not easy to setup this…

> [@Is it possible to allow only "delete" inhibiting the "disassociate" in a relationship?](https://community.forestadmin.com/t/is-it-possible-to-allow-only-delete-inhibiting-the-disassociate-in-a-relationship/6056/5):
>
> Hi Forest. Any update about this from your product board? Is this covered in the new @forestadmin/agent? Thank you, Matteo @morganperre I’m tagging you here because you liked the previous answer and the Forest Guy who answered me in march 2023 is now “anon###” so maybe at the moment he’s not a Forest Guy any more sweat_smile

> [@Matteo](#):
>
> It looks like there’s some permission problem, because in our logs we see that the backend is returning a http `403` error to Forest (as we can see with the Chrome dev tools):
> 
> With the _new_ agent, we had some struggle about this… and finally we found out that we could make this work by adding the _DELETE_ permission to the role for the collections `ExperienceTemplate` and `Idea`. **But we absolutely don’t want to allow the delete of these items!** And we’re quite sure that the disassociate operation has nothing to do with the record deletion.

You are absolutely right. I just check our code and the agent check that the user can delete to allow dissociate. But as we saw this is wrong since dissociating can only be **an update** …

> <https://github.com/ForestAdmin/agent-nodejs/blob/64bd49e34e75d391d96634916fa48eb333968e26/packages/agent/src/routes/modification/dissociate-delete-related.ts#L31>

I will circle back with our teams to find a clean solution. I will come back to you when we decide something.

* * *

> [@Matteo](#):
>
> With the new agent, we couldn’t exclude this model, because we understood that it’s needed to fulfil all the paths between model relationships on Forest side. So we didn’t exclude it. And we just hid the collection from the collection list in the main forest dashboard.

I imagine you tried the [excludes collection option of addDataSource](https://docs.forestadmin.com/developer-guide-agents-nodejs/data-sources/getting-started/partial-imports) am I right ?

> [@Matteo](#):
>
> But we had a couple of test with this collection permissions too and the observed behaviour does not change whichever setting we do: allowing all the (role related) permissions doesn’t fix. And the “realtionship” fields in the collection settings are NOT read only on both sides:

`Read-only` settings has you show is only a frontend layout customization (it only affects the frontend state).

Again, I will circle back we our team to solve the dissociate issue.

Kind regards,  
Morgan

---

_[View the full topic](https://community.forestadmin.com/t/migration-to-forestadmin-agent-permission-problems-with-disassociate-relationship/7510)._
