mollyim / mollyim-android

Enhanced and security-focused fork of Signal.
GNU Affero General Public License v3.0
1.7k stars 90 forks source link

Groups Grant All Users Admin Privileges by Default #388

Open inferenceus opened 5 days ago

inferenceus commented 5 days ago

Is there an existing request for this?

Feature description

When creating groups in Molly, all users are given admin access by default. This does not seem like a sane default, whether intentional or not.

Despite adding my own admins, every user of every one of my groups was permitted to change other users' admin privilege status and group information, which I had to manually change the settings of.

I believe all groups should have these permissions set to admins-only by default, which makes groups much more secure-by-default.