View Issue Details

This issue affects 1 person(s).
 4
IDProjectCategoryView StatusLast Update
17186Bug reportsUser / Groups / Rolespublic2021-03-18 15:19
ReporterDenisChenu Assigned Toc_schmitz  
PrioritynoneSeverityminor 
Status closedResolutionno change required 
Product Version4.4.13 
Summary17186: Set all CRUD permission "Users" didn't allow editing User
Description

Except super admin : there are no way to have a all user manager

Steps To Reproduce

As superadmin

  1. Create an user and give him all right on User and user groups Usertest
  2. Create 2 other user User1 and User2

As Usertest

  1. Go to user management
  2. See the list, no way to update
Additional Information

Checked with or without " Group member can only see own group: " on or off : same list
3.X have same issue

Capture d’écran du 2021-03-16 09-23-12 : right set on test user
Capture d’écran du 2021-03-16 09-23-28 : what user see

TagsNo tags attached.
Attached Files
Bug heat4
Complete LimeSurvey version number (& build)4.4.13
I will donate to the project if issue is resolvedNo
Browsernot relevant
Database type & versionnot relevant
Server OS (if known)not relevant
Webserver software & version (if known)not relevant
PHP Versionnot relevant

Users monitoring this issue

There are no users monitoring this issue.

Activities

c_schmitz

c_schmitz

2021-03-18 14:56

administrator   ~63427

This is exactly how it is supped to work, see documentation:

Users: A user can create, modify, and delete his own administration users with this permission. The newly created users cannot have higher permissions than the parent user. You will also not be able to edit users owned by other administration users. If this has to be done, then a Superadministrator permission has to be granted.

DenisChenu

DenisChenu

2021-03-18 15:19

developer   ~63429

Maybe review the sentence "Permission to create, view, update and delete users"

And what right give "Permission to view and update users" ?

With this permission : you don't have more right than any other user ?

Maybe best : keep only create + view. Other are not used.

Issue History

Date Modified Username Field Change
2021-03-16 09:24 DenisChenu New Issue
2021-03-16 09:24 DenisChenu File Added: Capture d’écran du 2021-03-16 09-23-12.png
2021-03-16 09:24 DenisChenu File Added: Capture d’écran du 2021-03-16 09-23-28.png
2021-03-16 09:24 DenisChenu Product Version 3.25.18 => 4.4.13
2021-03-17 08:13 DenisChenu Summary All permission fro Users didn't allow editing User => Set all CRUD permission "Users" didn't allow editing User
2021-03-18 14:56 c_schmitz Assigned To => c_schmitz
2021-03-18 14:56 c_schmitz Status new => closed
2021-03-18 14:56 c_schmitz Resolution open => no change required
2021-03-18 14:56 c_schmitz Note Added: 63427
2021-03-18 15:19 DenisChenu Note Added: 63429