Skip to content

Disable ability to add user to admin user group, unless user himself has admin rights #11208

Open
@vierkantemeter

Description

@vierkantemeter

Disable ability to add a user to the admin user group, unless the user who is trying to do this has admin rights himself. (Or; restrict users to add new users with higher permissions than they have themselves)

Now, content-editors with permissions to add new users can also create admin users, or give themselves admin rights.

This is a huge security flaw in my view, becasue I have content-editors who would like to.. experiment. ;)

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-securityproposalProposal about improvement aka RFC. Need to be discussed before start implementation.urgentThe issue requires attention and has higher priority over others.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions