← Back to team overview

mahara-contributors team mailing list archive

[Bug 492009] A change has been merged

 

Reviewed:  https://reviews.mahara.org/623
Committed: http://gitorious.org/mahara/mahara/commit/396ba897dbe1e5a1acf4fe6ed80f16220b4a357c
Submitter: Richard Mansfield (richardm@xxxxxxxxxx)
Branch:    master

commit 396ba897dbe1e5a1acf4fe6ed80f16220b4a357c
Author: Richard Mansfield <richard.mansfield@xxxxxxxxxxxxxxx>
Date:   Wed Aug 17 16:48:32 2011 +1200

    Remove can_become_admin check when changing group roles
    
    This function always returns true, and can be removed.  It's just a
    leftover from the attempt to prevent non-staff becoming controlled
    group admins (see bug #492009, bug #603044).
    
    Change-Id: Ib58aa4966f2cd94465dd657c081b51a12464f153
    Signed-off-by: Richard Mansfield <richard.mansfield@xxxxxxxxxxxxxxx>

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/492009

Title:
  Ordinary group members can be promoted to be an admin of "controlled"
  or "course" groups.

Status in Mahara ePortfolio:
  Fix Released

Bug description:
  Ordinary group members (those who are not site or institution admins
  or staff) can be promoted to be admins of "standard.controlled",
  "course.controlled" and "course.request" groups through
  Group->Members->"Change Role" interface (/group/changerole.php). This
  should not be permitted. When the ordinary user is promoted to be such
  admin, not only the error on group_get_grouptype_options() function
  call will pop-up (group type drop-down menu), as ordinary user can
  only be admin of invite/request/open standard groups, but also such
  user can remove original group admin and institution or site admin
  will end up having uncontrolled "course group".

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/492009/+subscriptions