Closed (won't fix)
Project:
Admin role
Version:
6.x-1.2
Component:
Code
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
14 Jul 2010 at 18:32 UTC
Updated:
14 Aug 2010 at 17:14 UTC
In some cases it is useful, when you can define, who is allowed to set the admin role.
For example you have a role, who can edit the user settings, but is not allowed to edit the permissions. If the role can set the admin role, then the person can hijack the whole system.
I add this feature / bug fix to module. Here is the patch for it. It would be nice, if some one can add this to the code.
| Comment | File | Size | Author |
|---|---|---|---|
| New File (if some problem exists with the diff file) | 2.02 KB | customweb | |
| Diff File | 618 bytes | customweb |
Comments
Comment #1
dave reidThe module follows the same policy as Drupal 7, which is anyone with 'administer users' can change the admin role settings.