View Issue Details

This bug affects 1 person(s).
 6
IDProjectCategoryView StatusLast Update
08840Feature requestsAuthenticationpublic2023-02-08 16:34
Reporterrolando_isidoro Assigned Toollehar  
PrioritynormalSeverityfeature 
Status feedbackResolutionopen 
Summary08840: SuperAdministrator users should be able to assign SuperAdministrator rights to other users
Description

In the "Manage users" manual page it reads:

"SuperAdministrator: This right can only be added or removed by the user called admin and grants full rights to the whole LimeSurvey installation. Please note: This right is very powerful and you should be very carfefully with granting this right."

http://manual.limesurvey.org/Manage_users#Setting_global_permissions_for_a_user

Other SuperAdministrator users besides the one called admin should also be able to grant or remove this right.

Tagspermissions, rights, SuperAdministrator, users
Bug heat6
Story point estimate0
Users affected %0

Users monitoring this issue

There are no users monitoring this issue.

Activities

DenisChenu

DenisChenu

2014-03-11 14:54

developer   ~29188

In favor with some exception : maybe by default it's the old way.

Because 'MAYBE' some user don't want it.

Then a setting or in plugin[*] ?

Denis

  • : i like plugin ;)
rolando_isidoro

rolando_isidoro

2014-03-12 11:42

reporter   ~29204

Denis, I don't really see the point of creating a plugin to define if non-admin SuperAdministrator users should be able to assign SuperAdministrator role to other users.

Btw, any SuperAdministrator user can change the admin user password, so if this a security matter there's a simple workaround for non-admin users to take over.

DenisChenu

DenisChenu

2014-03-12 11:45

developer   ~29205

<q> Btw, any SuperAdministrator user can change the admin user password, so if this a security matter there's a simple workaround for non-admin users to take over. </q>Another bug here ;).

But you're rigth : if this is able, then no need other restriction.

ollehar

ollehar

2023-02-08 16:34

administrator   ~73753

Already fixed?

Issue History

Date Modified Username Field Change
2014-03-11 13:11 rolando_isidoro New Issue
2014-03-11 13:12 rolando_isidoro Tag Attached: users
2014-03-11 13:12 rolando_isidoro Tag Attached: permissions
2014-03-11 13:12 rolando_isidoro Tag Attached: rights
2014-03-11 13:12 rolando_isidoro Tag Attached: SuperAdministrator
2014-03-11 14:54 DenisChenu Note Added: 29188
2014-03-12 11:42 rolando_isidoro Note Added: 29204
2014-03-12 11:45 DenisChenu Note Added: 29205
2023-02-08 16:34 ollehar Assigned To => ollehar
2023-02-08 16:34 ollehar Status new => feedback
2023-02-08 16:34 ollehar Note Added: 73753
2023-02-08 16:34 ollehar Bug heat 254 => 256
2023-02-08 16:34 ollehar Category Security => Authentication
2023-02-08 16:34 ollehar Story point estimate => 0
2023-02-08 16:34 ollehar Users affected % => 0
2023-02-08 16:34 ollehar Bug heat 256 => 6