emilienschultz / activetigger

MIT License
4 stars 0 forks source link

User Access and Deletion Permissions #114

Closed leomignot closed 1 week ago

leomignot commented 1 week ago

It looks like I can delete others accounts in the "Manage users and rights" section. I haven't tried performing the deletion, so there may already be a security measure in place. Is this behavior tied to the beta-test conditions or linked to the privileges of a manager role?

emilienschultz commented 1 week ago

Perfectly right. Good catch. I modified and now people can only see account they created. Only root can access all account.

emilienschultz commented 1 week ago

Crap. No, people need to see other accounts. I made the wrong fix :)

emilienschultz commented 1 week ago

Ok, you can see all the account but only delete those you have created, except you are root