Closed (fixed)
Project:
Admin role
Version:
6.x-1.x-dev
Component:
Code
Priority:
Normal
Category:
Task
Assigned:
Reporter:
Created:
26 Oct 2009 at 22:20 UTC
Updated:
9 Dec 2009 at 21:20 UTC
Jump to comment: Most recent file
Would it be posable in the next version to add permission control that would allow an admin user of a site the ability to decide which roles have access to the administration page for the Admin Role module, currently any user that has access to administration pages can access and change the Admin Role.
Thanks,
From: Azz McH
| Comment | File | Size | Author |
|---|---|---|---|
| #4 | 615336-adminrole-D7sync-D6.patch | 5.05 KB | dave reid |
Comments
Comment #1
aaronmchaleComment #2
dave reidSeems fair that the 'administer users' should be the permission for the adminrole page. This would match the D7 behavior:
Comment #3
dave reidNo patch = active
Comment #4
dave reidPeople should be able to upgrade from D6 + adminrole.module to plain D7 without losing functionality. That will entail:
1. Moving the admin role select box to the admin/user/settings page and getting rid of the page callbacks.
2. Renaming the adminrole_adminrole variable to user_admin_role.
3. Other misc cleanups.
Comment #5
dave reidComment #6
Leeteq commentedAs discussed here;
"Adminrole security hole: admins can assign themselves full permissions"
http://drupal.org/node/375954#new
- this is not only for "upgrading ease".
Comment #7
dave reidFixed in CVS.
Comment #8
aaronmchaleAll I want to know is, will this be fixed in a new release? Including http://drupal.org/node/375954.
Comment #9
dave reidYes it will.
Comment #10
aaronmchaleGood, when will the new release be available?
Comment #11
dave reidWhen I'm finished? Probably later today.
Comment #12
aaronmchaleGreat
Comment #13
dave reidNew releases created.