Bug #319
closed
system_usermanager privilege not working as expected
Added by Mizst Audens almost 15 years ago.
Updated over 11 years ago.
Category:
User Manager / Privileges
Description
Expected behavior:
Users without system_usermanager privilege -> send to change password page.
Users with system_usermanager privilege -> send to user manager page.
Actual behavior:
Users without system_usermanager privilege -> cannot access the page at all (redirected).
Users with system_usermanager privilege -> send to change password page.
Only admins with "all pages" privilege can access user manager page.
Consequence: Cannot assign personnel to user management duties without also giving them entire admin privileges.
I'm on a clean install of 2.0 beta Jan 22 livecd build.
- Target version set to 2.1
That's probably just how it's going to be for 2.0, if you need to manage local users you need full admin rights. Anyone who can manage users can assign themselves admin rights, or create a new account with admin rights, since there aren't any restrictions on what you can do on that page if you can access the page. I do see scenarios where you would want that, but that's probably not something we'll be able to accommodate for this release.
Then would it be possible to make it so that non-admin users with system_usermanager can grant only limited rights, such as only for captive portal access? An example where this would be immensely useful is allowing (non-IT) teachers to create accounts for internet access for their students, so the task of creating accounts for new students each year does not fall to a single IT personnel.
I understand that it will have to wait for the next version.
- Status changed from New to Feedback
- Assignee set to Renato Botelho
- % Done changed from 0 to 100
The original problem described in this ticket is fixed in 2.1. About the other change you are requesting, please open a new ticket set as "feature".
- Status changed from Feedback to Closed
Also available in: Atom
PDF