? Success

User tests: Successful: Unsuccessful:

avatar roland-d
roland-d
8 Jun 2016

Summary of Changes

Currently it is possible as a super user to remove your own super user rights. This causes you to be locked out from your own site.

Testing Instructions

  1. Login to the administrator section as Super User
  2. Go to System -> Global Configuration -> Permissions
  3. Click on the Super Users tab
  4. Set the Super User option to Denied
  5. Success and you are locked out :)
  6. Fix the database so you can login by going to ID 1 in the assets table and set core.admin to {"8":1}
  7. Apply the patch
  8. Login to the administrator section as Super User
  9. Go to System -> Global Configuration -> Permissions
  10. Click on the Super Users tab
  11. Set the Super User option to Denied
  12. You are informed you cannot demote yourself and you stay logged in

Calling the troops @andrepereiradasilva and @infograf768 ????

avatar roland-d roland-d - open - 8 Jun 2016
avatar roland-d roland-d - change - 8 Jun 2016
Status New Pending
avatar roland-d roland-d - change - 8 Jun 2016
Milestone Added:
avatar joomla-cms-bot joomla-cms-bot - change - 8 Jun 2016
Labels Added: ?
avatar infograf768 infograf768 - test_item - 8 Jun 2016 - Tested successfully
avatar infograf768
infograf768 - comment - 8 Jun 2016

I have tested this item successfully on 85836c6

This works fine for a SuperUser in Global as well as in component permissions.

Note: it does not work for other groups. For example a group with Administrator as parent trying to change his own permission gets a spin (js error) and no message.


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10758.

avatar brianteeman
brianteeman - comment - 8 Jun 2016

The error message I got was undefined

screen shot 2016-06-08 at 11 34 00


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10758.

avatar andrepereiradasilva
andrepereiradasilva - comment - 8 Jun 2016

@brianteeman are you using lates staging and refreshed the browser cache?

avatar andrepereiradasilva andrepereiradasilva - test_item - 8 Jun 2016 - Tested successfully
avatar andrepereiradasilva
andrepereiradasilva - comment - 8 Jun 2016

I have tested this item successfully on 85836c6

Works as described.
Also can confirm jean-marie results.


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10758.

avatar brianteeman
brianteeman - comment - 8 Jun 2016

It was staging from this morning. Will update again and retest

On 8 June 2016 at 18:09, andrepereiradasilva notifications@github.com
wrote:

I have tested this item successfully on 85836c6
85836c6

Works as described.

Also can confirm jean-marie results.

This comment was created with the J!Tracker Application
https://github.com/joomla/jissues at issues.joomla.org/joomla-cms/10758
https://issues.joomla.org/tracker/joomla-cms/10758.


You are receiving this because you were mentioned.
Reply to this email directly, view it on GitHub
#10758 (comment),
or mute the thread
https://github.com/notifications/unsubscribe/ABPH8UaEAqmiuFAWy6UUVIf2iAZwVJDuks5qJvc8gaJpZM4IxHy3
.

Brian Teeman
Co-founder Joomla! and OpenSourceMatters Inc.
http://brian.teeman.net/

avatar brianteeman brianteeman - test_item - 8 Jun 2016 - Tested successfully
avatar brianteeman
brianteeman - comment - 8 Jun 2016

I have tested this item successfully on 85836c6

Took a LOT of cache refreshes but i got there in the nd


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10758.

avatar andrepereiradasilva
andrepereiradasilva - comment - 8 Jun 2016

BTW maybe we should add ScriptVersion to permission.js ...

avatar infograf768 infograf768 - change - 8 Jun 2016
Status Pending Ready to Commit
avatar infograf768
infograf768 - comment - 8 Jun 2016

rtc. thanks.


This comment was created with the J!Tracker Application at issues.joomla.org/joomla-cms/10758.

avatar joomla-cms-bot joomla-cms-bot - change - 8 Jun 2016
Labels Added: ?
avatar wilsonge wilsonge - change - 8 Jun 2016
Status Ready to Commit Fixed in Code Base
Closed_Date 0000-00-00 00:00:00 2016-06-08 21:51:38
Closed_By wilsonge
avatar wilsonge wilsonge - close - 8 Jun 2016
avatar wilsonge wilsonge - merge - 8 Jun 2016
avatar joomla-cms-bot joomla-cms-bot - close - 8 Jun 2016
avatar joomla-cms-bot joomla-cms-bot - change - 8 Jun 2016
Labels Removed: ?

Add a Comment

Login with GitHub to post a comment