Change record status: 
Project: 
Introduced in branch: 
12.x
Description: 

Before

A loophole incorrectly allowed users with the Administer users (administer users) permission to assign roles, as well through a bulk operation. This meant they could grant any user any role for the site, including themselves. This issue did not affect the role assignment checkboxes found on individual user profiles, but did allow bulk updates of users to add roles. Most existing sites are affected by this issue.

After

The Administer users (administer users) permission no longer allows granting roles.

This affects any roles on your site that have Administer users (administer users), but not Administer permissions (administer permissions) permissions. Some users may lose access to grant/revoke roles to users. If roles were intentionally allowed to update other users' roles only with the Administer users (administer users) permission prior to this fix, these roles will need to be granted the Administer permissions (administer permissions) permission explicitly. Roles can be granted/revoked with one of the following options:

  • Assign Administer permissions (administer permissions) to those users - but only if they should essentially be full administrators of the site permissions and user roles.
  • Use a contributed project solution for assigning roles more safely, such as RoleAssign or Role Delegation.

Also, in the users administrative page (/admin/people), in the bulk operations for, actions adding or removing user roles are not exposed anymore for users without Administer permissions (administer permissions).

Impacts: 
Site builders, administrators, editors