unkeyed / unkey

Open source API management platform
https://go.unkey.com
Other
4k stars 468 forks source link

Permissions issue: Member can change role of other team members #549

Closed bipulpoudel closed 11 months ago

bipulpoudel commented 11 months ago

Preliminary Checks

Reproduction / Replay Link (Optional)

No response

Description

User with member role can change the role for other users in Settings-> Team page.

Steps to reproduce:

  1. Invite a member in Settings->Team page
  2. Invite with Role as "Member"
  3. Login with invited user.
  4. Visit Settings->Team page
  5. Member can change other user's role to "Admin".

Expected behavior:

User with role "Member" shouldn't be able to change role for other users.

Actual behavior:

User with role "Member" can change role for other users.

image

Environment

No response

bipulpoudel commented 11 months ago

I am working on this issue :)