'Manage Users' permission allows users to assign themselves to 'Admin' group #2250

Closed
opened 2026-02-05 03:27:59 +03:00 by OVERLORD · 2 comments
Owner

Originally created by @jackhadrill on GitHub (May 17, 2021).

Describe the bug
The 'Manage Users' permission allows users to assign themselves to the 'Admin' group.

Steps To Reproduce
Steps to reproduce the behavior:

  1. Assign a user to a group with the 'Manage User' permission.
  2. Login as that user.
  3. Click on the 'edit profile' button.
  4. Modify the group to whatever you want (including admin).

Expected behavior
I would expect 'Manage Users' to be able to only assign the roles that the user themselves is in.

Your Configuration (please complete the following information):

  • Exact BookStack Version (Found in settings): BookStack v21.04.4
  • PHP Version: 7.4
  • Hosting Method (Nginx/Apache/Docker): Nginx
Originally created by @jackhadrill on GitHub (May 17, 2021). **Describe the bug** The 'Manage Users' permission allows users to assign themselves to the 'Admin' group. **Steps To Reproduce** Steps to reproduce the behavior: 1. Assign a user to a group with the 'Manage User' permission. 2. Login as that user. 3. Click on the 'edit profile' button. 4. Modify the group to whatever you want (including admin). **Expected behavior** I would expect 'Manage Users' to be able to only assign the roles that the user themselves is in. **Your Configuration (please complete the following information):** - Exact BookStack Version (Found in settings): BookStack v21.04.4 - PHP Version: 7.4 - Hosting Method (Nginx/Apache/Docker): Nginx
Author
Owner

@ssddanbrown commented on GitHub (May 17, 2021):

Hi @jackhadrill,
We explicitly show a notice in the role configuration view to advise of this scenario.

Screenshot from 2021-05-17 20-43-11

@ssddanbrown commented on GitHub (May 17, 2021): Hi @jackhadrill, We explicitly show a notice in the role configuration view to advise of this scenario. ![Screenshot from 2021-05-17 20-43-11](https://user-images.githubusercontent.com/8343178/118546977-9fba8580-b750-11eb-85ca-6302e31af369.png)
Author
Owner

@ssddanbrown commented on GitHub (May 24, 2021):

Since there's been no follow-up I'm going to close this.

@ssddanbrown commented on GitHub (May 24, 2021): Since there's been no follow-up I'm going to close this.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/BookStack#2250