Skip to content

Users with edit user permission can make themselves admins #1965

@andreasjacobsen93

Description

@andreasjacobsen93

Bug Report

Current Behavior
If a moderator is assigned with the permission to edit users, the user is also able to make itself admin by editing and assigning the administrator role to itself.

Expected Behavior
Only administrators should be able to assign or remove the admin role on a user.

Environment

  • Flarum version: 0.1.0-beta.11.1

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions