This issue serves to track progress porting 6.x-1.0 to Drupal 7.

Comments

salvis’s picture

Title: RoleAssign for D7 » RoleAssign for D7 — BETA1
Version: 7.x-1.x-dev » 7.x-1.0-beta1
Status: Active » Needs review

We have BETA1 of RoleAssign.

 

Please test this version and provide feedback, both good and bad:

IF this module works for you, please let us know by adding a note to THIS issue below.

IF YOU FIND A BUG, please check the issues queue, and if it hasn't been reported yet, then OPEN A NEW ISSUE!

PLEASE do NOT add bug reports / questions to this issue here.

salvis’s picture

Title: RoleAssign for D7 — BETA1 » RoleAssign for D7 — BETA2
Version: 7.x-1.0-beta1 » 7.x-1.0-beta2

We have BETA2 of RoleAssign.

Prior versions of RoleAssign had (and other modules with similar functionality may still have) two vulnerabilities:

1. Users with the Administer users permission were able to manipulate and obtain access to the uid 1 account and other accounts having the Administer permissions permission, even if they were restricted by RoleAssign.

2. If they happened to also have the Administer modules permission, they were able to disable RoleAssign and thus obtain the ability to assign all roles.

BETA2 (as well as 6.x-1.x-dev) eliminates both of these vulnerabilities.

 

Please test this version and provide feedback, both good and bad:

IF this module works for you, please let us know by adding a note to THIS issue below.

IF YOU FIND A BUG, please check the issues queue, and if it hasn't been reported yet, then OPEN A NEW ISSUE!

PLEASE do NOT add bug reports / questions to this issue here.

salvis’s picture

Title: RoleAssign for D7 — BETA2 » RoleAssign for D7 — RC1
Version: 7.x-1.0-beta2 » 7.x-1.0-rc1

We have RC1 of RoleAssign.

RC1 has some clean-up work that should not result in any functional changes. Nonetheless, this is the last chance to provide feedback before the 1.0 release. We currently have 150 sites using the D7 version and no one has cared to post a comment yet...

 

Please test this version and provide feedback, both good and bad:

IF this module works for you, please let us know by adding a note to THIS issue below.

IF YOU FIND A BUG, please check the issues queue, and if it hasn't been reported yet, then OPEN A NEW ISSUE!

PLEASE do NOT add bug reports / questions to this issue here.

Anonymous’s picture

Used RC1 on a production site and so far it seems fine. Thanks.

salvis’s picture

Thank you, sjhuda!

Everyone please note #1356964: Hide the Administrator role selection in admin/config/people/accounts unless the user has the 'administer permissions'. Add your comments there if you want, not here, please!

salvis’s picture

Title: RoleAssign for D7 — RC1 » RoleAssign for D7 — RC2
Version: 7.x-1.0-rc1 » 7.x-1.0-rc2

RC1 is running on over 1000 known sites. Nevertheless, there have been a few minor issues that have been fixed, and that's why we need another release candidate.

Please check out RC2 and provide feedback, both good and bad, so that we can quickly go to 1.0.

IF this module works for you, please let us know by adding a note to THIS issue below.

IF YOU FIND A BUG, please check the issues queue, and if it hasn't been reported yet, then OPEN A NEW ISSUE!

PLEASE do NOT add bug reports / questions to this issue here.

karenann’s picture

RC2 tested on a local 7.16 install with no issue.

salvis’s picture

Title: RoleAssign for D7 — RC2 » RoleAssign for D7
Version: 7.x-1.0-rc2 » 7.x-1.0
Status: Needs review » Fixed

Thank you, karenann!

RC2 has turned into 1.0 with no changes.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.