mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #05921
[Bug 492009] A change has been merged
Reviewed: https://reviews.mahara.org/623
Committed: http://gitorious.org/mahara/mahara/commit/396ba897dbe1e5a1acf4fe6ed80f16220b4a357c
Submitter: Richard Mansfield (richardm@xxxxxxxxxx)
Branch: master
commit 396ba897dbe1e5a1acf4fe6ed80f16220b4a357c
Author: Richard Mansfield <richard.mansfield@xxxxxxxxxxxxxxx>
Date: Wed Aug 17 16:48:32 2011 +1200
Remove can_become_admin check when changing group roles
This function always returns true, and can be removed. It's just a
leftover from the attempt to prevent non-staff becoming controlled
group admins (see bug #492009, bug #603044).
Change-Id: Ib58aa4966f2cd94465dd657c081b51a12464f153
Signed-off-by: Richard Mansfield <richard.mansfield@xxxxxxxxxxxxxxx>
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/492009
Title:
Ordinary group members can be promoted to be an admin of "controlled"
or "course" groups.
Status in Mahara ePortfolio:
Fix Released
Bug description:
Ordinary group members (those who are not site or institution admins
or staff) can be promoted to be admins of "standard.controlled",
"course.controlled" and "course.request" groups through
Group->Members->"Change Role" interface (/group/changerole.php). This
should not be permitted. When the ordinary user is promoted to be such
admin, not only the error on group_get_grouptype_options() function
call will pop-up (group type drop-down menu), as ordinary user can
only be admin of invite/request/open standard groups, but also such
user can remove original group admin and institution or site admin
will end up having uncontrolled "course group".
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/492009/+subscriptions