Project

General

Profile

Actions

Bug #28867

closed

As impersonated user, it is possible to delete impersonating user

Added by Ondřej Pražák about 5 years ago. Updated over 4 years ago.

Status:
Closed
Priority:
Normal
Category:
Users, Roles and Permissions
Target version:
-
Difficulty:
Triaged:
No
Fixed in Releases:
Found in Releases:

Description

Steps to reproduce:

1) Have 'admin' user and 'manager' user (with Manager role) both in the same taxonomies
2) log in as admin
3) impersonate manager
4) delete admin when impersonating manager
5) admin is deleted and user is now logged in as manager

It should not be allowed to delete impersonating user as impersonated user.

Actions

Also available in: Atom PDF