[Koha-bugs] [Bug 7648] New: staff can make themselves superlibrarians

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Tue Mar 6 04:16:55 CET 2012


http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=7648

          Priority: P5 - low
 Change sponsored?: ---
            Bug ID: 7648
                CC: gmcharlt at gmail.com
          Assignee: kyle.m.hall at gmail.com
           Summary: staff can make themselves superlibrarians
        QA Contact: koha.sekjal at gmail.com
          Severity: normal
    Classification: Unclassified
                OS: All
          Reporter: nengard at gmail.com
          Hardware: All
            Status: NEW
           Version: master
         Component: Patrons
           Product: Koha

This seems like an oversight to me, but if you give a staff patron the ability
to set permissions for other staff members they can then update their own
permissions and make themselves superlibrarians.  I would say that only
superlibrarians can make other staff superlibrarians, and I'd go even further
to say that only superlibrarians should be able to change their own permissions
- but I think this is probably due for some discussion either way because it's
a pretty big oversight.

-- 
You are receiving this mail because:
You are watching all bug changes.


More information about the Koha-bugs mailing list