I'm not sure if I'm looking for the right terms, but I can't seem to find any information on setting up site Administrators.
I've read that you shouldn't use the UID1 user account (aka first user, Root, Super Administrator etc) for day to day use. Fine, that makes sense. But what if I want to set up a lower level Administrator account, that can do almost everything that the Root admin can do except lock-out or change the Root admin's account, email address or access permissions? I want this lower level admin to be able to manage the whole site except for a few key things.
Here's my situation: I've built a site with Drupal for a client. It's now time to hand over the controls and let their IT guys deal with their, hosting, users and content. But, the site isn't 100% finished yet, as there are still a few little things here and there that will of course pop-up when the site goes into production use. I will of course fix these issues, but if these new IT guys start poking around in the templates, modules, and settings, things may go foobarred. And I may be in a bit of pickle if I can't figure out how to keep control.
I also expect (hope) that they will come back to me for the 2nd phase in a few months.
The cheque is also 'in the mail', but we haven't received it yet (though we have received 2 previous payments), so there's that issue.
So here's what I'm looking for: to setup a limited administrator or "webmaster" account that can do almost everything except lock me out. I guess I'm looking for a back-door. Right now it seems as though the Access Control area is limited to "ON or OFF" type settings. The User Module only gives "administer users" 'yes' or 'no'. I'd like it to say "administer users (except UID1/Root Admin)".
Is there any information, or handbook, or something that goes into extreme detail on this? Maybe even an administration module (that I may have missed).
I'm using 4.6.
Any help or pointers would be extremely helpful.
Cheers!
Comments
You need to use roles to do this
Under administer > access controls > roles you can create an admin role and give it as many or as few permissions as you need. I'm not 100% sure that you can create a role that can touch all users *except* the super user, though.
Your back door option is to use PHPmyAdmin to backup the entry for UID=1 and if someone messes it you can restore that line manually to the user table. Not perfect, but I'm tempted to ask whether you trust someone with admin privileges if you can't trust them not to sabotage the top level user, but that is a different issue. They would have to intentionally tamper with the first account to alter it.
Good back door option
Thanks for your quick response!
I hadn't thought about manually restoring that line manually, but that's a pretty good idea! I definitely give that a try.
BTW I have already made a couple of Roles (one being "Webmaster"), but like you noted, you can't specify "all *except* the super user".
To answer your question about trust, this is exactly why I'd like to not give someone I don't completely trust(or even know) full Administration control, but instead a limited administration role. It just seems strange that such a powerful CMS has not much in the way of a proper user/permission control system. It kind of reminds me of Windows XP - a Guest account or an Adminstrator account. I know to go into administration settings and create limited super user accounts and such, but not everyone knows how to do that (nor should they need to). I would think Drupal should have pre-defined rolls setup beyond anonymous, authorized and administrator. Maybe that's in work for the next version of Drupal?
thx again.
I don't think so
You can't give a user admin users without giving them access to UID1 unless there's some contrib module that I've never heard of. If it's just a matter of being able to get back in the site, you can do that as long as you have database access as the other post mentioned.
I went 'round and 'round with some people about why I use UID1 for my regular admin account and this was one of my biggest reasons. I need access to users on a regular basis so there's not much point in _not_ using UID1 if I make another admin account that can admin users anyway.
Unfortunately, I'm not aware of any improvement in this area with 4.7.
Michelle
Why shouldn't UID1 be used day to day?
1. User ID 1
Yes, I recall reading that somewhere as well. However, could someone please explain to me why that's the case? On drupal.org, for example, it appears to me that Dries uses the UID1 for day to day use, as you can see by moving your mouse over his name here when he posted the Drupal 5.0 beta 1. (You should see http://drupal.org/user/1 as you move your mouse over Dries' name.)
2. A limited administrator or "webmaster" account
As to am's issue, I didn't check 4.6 but if you're now running 4.7, have you taken a look at the RoleAssign module? I just looked at it briefly so you'll have to figure out if and how it works. If you develop a solution to your issue, I (and others) would appreciate it if you could post your solution here. It could be helpful to others.
Thank you.
Walt Esquivel, MBA; MA; President, Wellness Corps; Captain, USMC (Veteran)
$50 Hosting Discount Helps Projects Needing Financing