Skip to content

"Read-only" account can do things for which he has no rights #54

Open
@dktmb

Description

@dktmb

Describe the bugs

  1. Read-only can put BANs, INVITEs and EXCEPTs on channels
  2. Rehash a server doesn't return "access issue"

To Reproduce
Steps to reproduce the behavior:
1a. Create a "read-only" user
1b. Go on "Channels" page and you can ban, invite or except users on a channel
1c. It works ! Ban, invite or except is effective

2a. Go on "Servers" page and click on "rehash" button.
2b. The rehash was not made but the page act like it was (refresh, ...) and no error message.

Expected behavior
1.
The buttons "BAN", "INVITE" and "EXCEPT" would be unclickable as "Change settings" in "Settings/modes" tab

2.
When a "read-only" user try to do something that he had no rights for, he obtain the message "Could not do that: Permission denied" or something like that as when he tries to put a server ban.

Desktop (please complete the following information):

  • OS: Debian 12
  • Browser : Firefox, Chrome
  • Version : browsers and webpanel are up to date

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions