View Issue Details

This bug affects 1 person(s).
 260
IDProjectCategoryView StatusLast Update
08399Bug reportsSecuritypublic2013-11-25 16:22
Reporterserzas Assigned ToDenisChenu  
PrioritynormalSeverityminor 
Status closedResolutionfixed 
Product Version2.05 RC 
Target Version2.05+Fixed in Version2.05+ 
Summary08399: Admin can't edit another admin created user rights
Description

When superadmin try edit global permission of user created by another superadmin user, appear error "Access denied! You are not allowed to perform this operation!"

Steps To Reproduce

Login with superadministrator User "A"
Create user "B" with superadministrator user global rights
Login with user "B"
Create normal user "C"
Loguot user "B"
Login with superadministrator User "A"
Try edit global permission of user "C"

TagsNo tags attached.
Attached Files
survey_error.jpg (42,844 bytes)   
survey_error.jpg (42,844 bytes)   
Bug heat260
Complete LimeSurvey version number (& build)Version 2.05RC6 Build 131105
I will donate to the project if issue is resolvedNo
BrowserChrome, IE
Database type & versionMySQL
Server OS (if known)Centos 6
Webserver software & version (if known)apache API version 20051115
PHP Version20090626

Relationships

related to 08373 closedc_schmitz setting global permission for admin users - causes error 

Users monitoring this issue

Activities

DenisChenu

DenisChenu

2013-11-22 13:39

developer   ~27319

Fix committed to 2.05 branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=13487

DenisChenu

DenisChenu

2013-11-22 13:42

developer   ~27321

See : http://bugs.limesurvey.org/view.php?id=8373

c_schmitz

c_schmitz

2013-11-25 15:39

administrator   ~27372

2.05RC7 released.

Related Changesets

LimeSurvey: 2.05 2dc9484f

2013-11-22 12:39:20

DenisChenu

Details Diff
Fixed issue 08399: Admin can't edit another admin created user rights
Dev: removing the die and put some FlashMessage
Dev: Need decision for the rigth of each user
Dev: When deleting a user : search for 1st user without parent : this one can not be the initial super admin (good chance, but not sure)
Dev: any superadmin can update another superadmin (except initial ?)
Dev: Any superadmin can set super admin to another user (in 2.0 : only initial super admin can do it)
Affected Issues
08399
mod - application/controllers/admin/useraction.php Diff File

LimeSurvey: 2.05 ab9e0ee7

2013-11-25 15:21:15

DenisChenu

Details Diff
Dev: 2dc9484ffa15551ac0a22468664dbc81b187daa7 child
Dev: 08399 findByAttributes return an object
Affected Issues
08399
mod - application/controllers/admin/useraction.php Diff File

Issue History

Date Modified Username Field Change
2013-11-22 08:48 serzas New Issue
2013-11-22 08:48 serzas File Added: survey_error.jpg
2013-11-22 08:51 mantas917 Issue Monitored: mantas917
2013-11-22 09:05 serzas Issue Monitored: serzas
2013-11-22 11:28 c_schmitz Target Version => 2.05+
2013-11-22 12:02 DenisChenu Issue Monitored: DenisChenu
2013-11-22 12:03 DenisChenu Relationship added related to 08373
2013-11-22 12:05 DenisChenu Assigned To => DenisChenu
2013-11-22 12:05 DenisChenu Status new => assigned
2013-11-22 13:39 DenisChenu Changeset attached => LimeSurvey 2.05 2dc9484f
2013-11-22 13:39 DenisChenu Note Added: 27319
2013-11-22 13:39 DenisChenu Resolution open => fixed
2013-11-22 13:42 DenisChenu Note Added: 27321
2013-11-22 13:42 DenisChenu Status assigned => resolved
2013-11-22 13:42 DenisChenu Fixed in Version => 2.05+
2013-11-25 15:39 c_schmitz Note Added: 27372
2013-11-25 15:39 c_schmitz Status resolved => closed
2013-11-25 16:22 DenisChenu Changeset attached => LimeSurvey 2.05 ab9e0ee7
2021-08-02 16:47 guest Bug heat 254 => 260