Uploaded image for project: 'Ibexa IBX'
  1. Ibexa IBX
  2. IBX-4543

[Corporate account] User without company admin role has active buttons 'change role' and 'deactivate'

    XMLWordPrintable

Details

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 4.4.2
    • 4.3.0, 4.3.x-dev
    • None

    Description

      Preconditions:

      • Added company
      • Added user to company with role 'Company buyer'

      Steps to reproduce:

      1. Log in to  HOST/corporate/customer-portal/customer-center as user with 'Company buyer' role.
      1. Go to Members / Companies / Members.
      2. Verify 'De-activate' and 'Change role' buttons.
      3. Try to deactivate user or change role to 'Company admin'.

      Actual result:
      See attached screenshots.

      • Buttons 'De-activate' and 'Change role' are active for user with 'Company buyer' role 
      • User can attempt to change the roles and de-activate / activate users

      Expected result:

      • Buttons 'De-activate' and 'Change role' are NOT active for user with 'Company buyer' role 
      • User cannot attempt to change the roles and de-activate / activate users

       

      Edit:
      I guess editing members by user with 'Company buyer' role shouldn't be possible as well (he can only edit himself).

      Designs

        Attachments

          Activity

            People

              Unassigned Unassigned
              bogdan.mazur@ibexa.co Bogdan Mazur
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: