Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Change user without permissions #11971

Closed
M4uRoDev opened this issue Sep 6, 2018 · 2 comments
Closed

Change user without permissions #11971

M4uRoDev opened this issue Sep 6, 2018 · 2 comments
Assignees

Comments

@M4uRoDev
Copy link

M4uRoDev commented Sep 6, 2018

Description:

The chat administrator has the option to change the user disabled, however, through the mobile application of Rocket.Chat, you can make the same modification of this field, this also results in the web application being frozen and it must be refreshed.

Steps to reproduce:

It is unnecessary, you should simply try to change your user through the mobile application.

Expected behavior:

Do not allow to change the user name through the application referring to the configuration parameters of the application.

Actual behavior:

It does not perform the permissions check and also allows the user to change.

Server Setup Information:

  • Version of Rocket.Chat Server:
  • Operating System:
  • Deployment Method:
  • Number of Running Instances:
  • DB Replicaset Oplog:
  • NodeJS Version:
  • MongoDB Version:

Additional context

Relevant logs:

@ggazzo ggazzo added this to the 0.70.0 milestone Sep 11, 2018
@MarcosSpessatto
Copy link
Member

MarcosSpessatto commented Sep 17, 2018

@M4uRoDev I think this issue has been fixed in this PR, which was included in version 0.69.3.

CC: @ggazzo

@theorenck theorenck modified the milestones: 0.70.0, Short-term Dec 12, 2018
@ggazzo ggazzo modified the milestones: Short-term, 0.73.0 Dec 13, 2018
@ggazzo ggazzo self-assigned this Dec 13, 2018
@MarcosSpessatto
Copy link
Member

@M4uRoDev can you please test it again with the latest version?

@theorenck theorenck removed this from the 0.73.0 milestone Mar 27, 2019
@ggazzo ggazzo closed this as completed Oct 17, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants