Skip to content
This repository has been archived by the owner on Feb 12, 2018. It is now read-only.

restricting roles using "Allowed Roles" does not stop user from deleting other user from ALL roles #32

Open
pwegrzy opened this issue Mar 18, 2015 · 0 comments

Comments

@pwegrzy
Copy link

pwegrzy commented Mar 18, 2015

anyone who has access to the "Roles" tab in the module for any Role can remove another user from ANY role, not just the ones selected via "Allowed Roles". This includes removing them even from the "Administrator" role.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants