Actions
Bug #27211
openCannot remove all rights from a user who has a single role, from the User management GUI
Status:
New
Priority:
To review
Assignee:
-
Category:
Security
Target version:
-
Pull Request:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
To do
Regression:
No
Description
When a user is initially created with the GUI, it is created with “no rights”.
As soon as the user has been given one role, it is not possible to remove the only role the user has, because :
- The system refuses to delete the only role attributed to the user ;
- If one tries to add “no rights” again, it is removed when pressing [Save] as the user still has some other rights.
- It is impossible to remove the only rights the user have after having added “no rights” without having saved.
So it is possible to add a different role to a user, then remove the previous one, but it is not possible to remove all rights.
All that can be done is disable or remove the user.
No data to display
Actions