Moderators can use "Account Types" to become admins

sza - August 20, 2007 - 16:07
Project:Account Types
Version:5.x-1.1
Component:Code
Category:bug report
Priority:normal
Assigned:sza
Status:closed
Description

Users who has access to user module for administer users can simply modify account type of ANY user without limit. Even if they can't "view accounttypes" in accounttypes module.

#1

rconstantine - August 20, 2007 - 17:42

You're talking about the user_edit form, right? Looks like I need to change the permission from "administer users" to "administer access control". Thanks.

#2

rconstantine - August 20, 2007 - 17:46
Status:active» fixed

Fixed it. Will be in next upload.

#3

sza - August 20, 2007 - 18:22

You're talking about the user_edit form, right?

Yes.

Fixed it. Will be in next upload.

Ok.

#4

Anonymous - September 5, 2007 - 07:11
Status:fixed» closed
 
 

Drupal is a registered trademark of Dries Buytaert.