user/*/delete and user/*/edit work as expected
but
admin/user/user page, section "Update options"
gives access to edit/block/delete any user, even user/1

CommentFileSizeAuthor
#4 AdministerUsersByRole-EditDenied.png40.37 KBsmokris
Support from Acquia helps fund testing for Drupal Acquia logo

Comments

Rafał Ch’s picture

Title: Allow any edit/block/delete » Allows any edit/block/delete
smokris’s picture

Assigned: Unassigned » smokris

Bulk deletion of users from the admin/user/user page is fixed in 6.x-0.9.

I'll backport this to the 5.x version.

smokris’s picture

Bulk deletion of users from the admin/user/user page is fixed in 5.x-1.0.

smokris’s picture

Regarding editing: On the admin/user/user page, "edit" links are still shown, but if you click the "edit" link, it should give an error message saying "You do not have permission to edit user x." (See attachment.)

Regarding blocking/unblocking: Yes, this is a problem. I'm working on a fix for it.

smokris’s picture

Status: Active » Fixed

Blocking/unblocking via admin/user/user is fixed in 5.x-1.1 and 6.x-1.1.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.