Support the paths provided by User Create by Role. The patch just follows the existing logic, effectively replacing the core "administer users" permission with "create users" for each role.

CommentFileSizeAuthor
support_user_create_by_role-0.patch995 bytesimclean

Comments

imclean created an issue. See original summary.

adamps’s picture

Status: Needs review » Closed (won't fix)

Hi @imclean thanks for the patch.

However I'm not convinced it is safe. Who is to say that the site administrator wanted the sub-admin to be able to create users with those roles?

As I understand it, if you install the "user create by role module" it simply creates a convenience link to create users with other roles. However only an admin is able to use it.

So as far as I can see, neither this module or the other on its own allows anyone other than an admin to change the role of any user. So it doesn't seem right that if you install both modules, suddenly this changes. Some other websites may have both modules installed and have carefully checked that the sub-admin cannot use the links to create other roles. I don't see that we can suddenly change that behaviour.

Perhaps you want a module like role delegation?

Or another option, as far as I can see there is nothing to stop you adding this code in a hook in your own custom module.

Sorry that I can't help you, but hopefully you can understand why. Of course feel free to re-open if you have a counter-argument.

imclean’s picture

@AdamPS, yeah that's a good point. User Create by Role is a pretty blunt instrument, just convenient.

I was hoping (in vain) to avoid 3 contrib modules just for basic user functions, one of which (Role Delegation) isn't really maintained any more.

On that point (and I've seen at least one related issue here), permissions to create users of each role within this module would be handy. Current recommendation is to use Role Delegation, which is more full featured in that respect.

I'd say creating a user is part of "administering" users, but that's probably a discussion for elsewhere.

Thanks for the prompt feedback.

imclean’s picture

What is the purpose of the "create user" permission if it isn't related to any of the other role related permissions? If a certain role can create a user, what role should/will that user have?

adamps’s picture

The create user permission allows creating of users with no roles.

Role delegation provides a permission to assign/remove each role. Together with this module that gives you the complete set of permissions.

A separate permission to create a user with each role just seems like duplication of the above. It permits the awkward situation that you might not be able to undo a create you did by mistake.

I agree it would be nice if Role Delegation had a more active maintainer, but I've not got time to volunteer right now.

Yes I share your feeling that there can be too many contrib modules, but I doubt it's practical to combine this and role delegation at this stage. Some sites use one, some the other, some both; where would all the code end up; what if a site upgrades one module not the other; etc.

I would say you need 2 modules for basic user functions. "User Create by Role" looks like more of a convenience wrapper than a basic function.

adamps’s picture

8.x-3.x adds support for assigning of selected roles