Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do not permit user XML import to import with role_id = ROLE_ID_SITE_ADMIN #10738

Open
asmecher opened this issue Dec 18, 2024 · 1 comment
Open
Assignees
Labels
Bug:2:Moderate A bug that is causing problems for a substantial minority of users.
Milestone

Comments

@asmecher
Copy link
Member

asmecher commented Dec 18, 2024

Describe the bug
The XML import process can current import users with ROLE_ID_SITE_ADMIN, though the context ID is set to a non-zero value (unlike legitimate admin users). These imports should be prevented.

What application are you using?
OJS and OMP 3.3.0-x and 3.4.0-x (and probably prior)

Special thanks to Hendra and the team at OpenJournalTheme.com for identifying this issue.

@asmecher asmecher added the Bug:2:Moderate A bug that is causing problems for a substantial minority of users. label Dec 18, 2024
@asmecher asmecher added this to the 3.3.0-21 milestone Dec 18, 2024
@asmecher asmecher self-assigned this Dec 18, 2024
asmecher added a commit to pkp/ojs that referenced this issue Dec 19, 2024
asmecher added a commit to pkp/omp that referenced this issue Dec 19, 2024
asmecher added a commit to pkp/ops that referenced this issue Dec 19, 2024
@Tribunal33
Copy link

@asmecher has this been fixed? I see some commits and are there any testable steps?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug:2:Moderate A bug that is causing problems for a substantial minority of users.
Projects
None yet
Development

No branches or pull requests

2 participants