Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Domain admin can disable own account #260

Open
kingfisher63 opened this issue May 15, 2019 · 1 comment
Open

Domain admin can disable own account #260

kingfisher63 opened this issue May 15, 2019 · 1 comment

Comments

@kingfisher63
Copy link

kingfisher63 commented May 15, 2019

A domain admin can lock himself out by disabling his own account. The Site Admin then has to (temporarily) designate another account as the domain admin or re-enable the account using a database management tool like phpMyAdmin.

Suggested behavior: a domain cannot disable his own account.

Since an domain can have multiple administrators, it may be even better to enforce the rule 'a domain must have at least one enabled admin account'.

@rimas-kudelis
Copy link
Collaborator

Nice finding, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants