No Code Attached Yet
avatar Borgas
Borgas
11 May 2022

Steps to reproduce the issue

Create user group (parent of public)
Create user level
Assign user group to new user level and Special (added both)

tutorial followed for this steps was this tutorial

Expected result

I have no idea. Just exploring this user group thing

Actual result

User assigned to this user group can not edit is own "user groups" but is allowed to edit the groups of other users.

He cannot become a super user, but he can go to another user and assign him as super user.

System information (as much as possible)

Joomla version - Lastest version, fresh install 4.1.3 with no extra installs, just the core version
PHP 7.4.29
MySQLi 5.7.38
Colocar em cache Disabled
Gzip Disabled

avatar Borgas Borgas - open - 11 May 2022
avatar joomla-cms-bot joomla-cms-bot - change - 11 May 2022
Labels Added: No Code Attached Yet
avatar joomla-cms-bot joomla-cms-bot - labeled - 11 May 2022
avatar chmst
chmst - comment - 11 May 2022

Parent of public is not possible. You mean public is the parent of your user group?
I think that you have allowed too much in configuration permissions. Could you please post a screenshot of the permissions?

avatar Borgas
Borgas - comment - 11 May 2022

Parent of public is not possible. You mean public is the parent of your user group? I think that you have allowed too much in configuration permissions. Could you please post a screenshot of the permissions?

1
2

This user, if goes to back-end, he cannot change his users permissions, but can access to another user, and modify that user permission
3

avatar chmst
chmst - comment - 11 May 2022

Which permissions do you see here

grafik

and in user permissions?

grafik

avatar Borgas
Borgas - comment - 11 May 2022

4
5

avatar chmst
chmst - comment - 12 May 2022

Your user seems to have permission for editing everything. He is also in a group Socios, this makes a big difference if this group has more permissions.

avatar Borgas
Borgas - comment - 12 May 2022

Your user seems to have permission for editing everything. He is also in a group Socios, this makes a big difference if this group has more permissions.

Thank you for, reply, but removed from all other groups, and levels (i have removed from special and configure everything to have access [toolbar, menus etc]

News prints of configuration, and seems strange this options
1
2
3
4

In his profile, he cannot manage his level
5

In another user, he can give any level
6

avatar drmenzelit
drmenzelit - comment - 12 May 2022

The user "Marco Ascensao" belongs to different groups, that can make trouble if the permissions are different in each group

avatar Borgas
Borgas - comment - 12 May 2022

The user "Marco Ascensao" belongs to different groups, that can make trouble if the permissions are different in each group

Hi, thank you for reply.

Even in a user "registered" the user as acess to all levels

Teste - User with privileges and is going to visit ->Teste1

1

Result page
2

I dont know if this was suppose to happen, i don´t play Joomla since 1.7 version
I´m just digging to find a way for a user with privileges be able to upgrade a registered user to another level, but not admin.
Like a registered user and a paywall

3

avatar drmenzelit
drmenzelit - comment - 13 May 2022

Normally a user in Registered group has no access to the backend. Something is wrong with your settings.

avatar chmst chmst - change - 13 May 2022
Status New Closed
Closed_Date 0000-00-00 00:00:00 2022-05-13 10:02:07
Closed_By chmst
avatar chmst chmst - close - 13 May 2022
avatar chmst
chmst - comment - 13 May 2022

@Borgas I suggest to ask in forum.joomla.org. The supporters there are very good with ACL problems. Give them a link to this issue.
I close this for now as it is not a joomla core problem. It can be re-opened if necessary.

avatar Borgas
Borgas - comment - 13 May 2022

Normally a user in Registered group has no access to the backend. Something is wrong with your settings.

Hello, it´s not the registered who as access.

User 1 - Registered
Manager 1 - Manager

Manager 1 can go to back-end and CAN NOT edit is group in is profile
Manager 1 can go back-end and VISIT User 1 profile, and tell is a Higher Manager than is own

For me, this shouldn´t be possible. Manager should only be able to assign until is level...not higher.

avatar drmenzelit
drmenzelit - comment - 13 May 2022

Try the same on a fresh installed Joomla site, before doing changes on your own. If that still happens, then it is probably a bug.

avatar Borgas
Borgas - comment - 13 May 2022

Try the same on a fresh installed Joomla site, before doing changes on your own. If that still happens, then it is probably a bug.

Hello, thank you for reply

It´s a fresh install, no "extra things" installed, just core Joomla. And updated to latest version
That´s why i open this ticket here, not in forum.

I think no one tried to replicate the issue. Maybe my english is not so good to explain the steps

avatar drmenzelit
drmenzelit - comment - 13 May 2022

No, it is not a clean install, you have already changed the user groups. And as I told you, if an user is in several groups with different permissions, the higher permission will won.

Add a Comment

Login with GitHub to post a comment