You are not logged in.

Announcement

 Téléchargez la dernière version stable de GLPI      -     Et vous, que pouvez vous faire pour le projet GLPI ? :  Contribuer
 Download last stable version of GLPI                      -     What can you do for GLPI ? :  Contribute

#1 2024-05-22 14:01:28

mmoral
Member
Registered: 2023-12-28
Posts: 50

Error updating email of user

Good Morning,

Some users have a profile with the next checks selected in administration --> Users: READ    UPDATE    CREATE    DELETE    PURGE
The users can update all fiels, but fail with the field email.

In Administration --> Logs
Appear a entry that the user modify a item of Users with the correct user ID, but in really the action failed and the email have not updated.
But in the log it appears as if it was done correctly.

Regards

Offline

#2 2024-05-22 14:37:22

cconard96
Moderator
Registered: 2018-07-31
Posts: 2,809
Website

Re: Error updating email of user

Emails can only be changed by the user themselves or changed a user with more permissions than them.


GLPI Collaborator and Plugin Developer.
My non-English comments are automated translations. Sorry for any confusion that causes.
Mes commentaires non anglais sont des traductions automatiques. Désolé pour toute confusion qui cause.
Mis comentarios que no están en inglés son traducciones automáticas. Perdón por cualquier confusión que cause.

Offline

#3 2024-05-22 14:46:46

mmoral
Member
Registered: 2023-12-28
Posts: 50

Re: Error updating email of user

Hello,

More permissions than: READ    UPDATE    CREATE    DELETE    PURGE ?

So, why does it appear in the log that the action was done correctly?, if the user does not have permissions

Regards

Last edited by mmoral (2024-05-22 14:46:57)

Offline

#4 2024-05-22 14:54:21

cconard96
Moderator
Registered: 2018-07-31
Posts: 2,809
Website

Re: Error updating email of user

No. The comparison takes into account all permissions available in every profile for both users.
A user's email is directly related to authentication, so it shouldn't be able to be modified by just anyone with the UPDATE right for users as it would lead to privilege escalation.
Imagine if an Admin with the ability to update users (to adjust title, comments, etc) could change a Super-Admin user's email address and then have a forgotten password notification sent to one of their own emails.

The update is counted as a success because the email fields are just transparently removed from the changes if the permission check fails rather than blocking the entire update.


GLPI Collaborator and Plugin Developer.
My non-English comments are automated translations. Sorry for any confusion that causes.
Mes commentaires non anglais sont des traductions automatiques. Désolé pour toute confusion qui cause.
Mis comentarios que no están en inglés son traducciones automáticas. Perdón por cualquier confusión que cause.

Offline

#5 2024-05-22 15:06:38

mmoral
Member
Registered: 2023-12-28
Posts: 50

Re: Error updating email of user

Thanks for the explain!!

Offline

Board footer

Powered by FluxBB