#24567 closed Bug (invalid)
/admin/auth/user/add/ requires "auth | user | Can change user" permission
| Reported by: | Michael Angeletti | Owned by: | nobody |
|---|---|---|---|
| Component: | contrib.admin | Version: | 1.8 |
| Severity: | Normal | Keywords: | |
| Cc: | Triage Stage: | Unreviewed | |
| Has patch: | no | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
I'm getting a 403 when I visit the /admin/auth/user/add/ with a staff User that has only auth | user | Can add user permission. After adding auth | user | Can change user, I'm able to access the aforementioned URL without issue.
Change History (3)
comment:1 by , 11 years ago
| Resolution: | → invalid |
|---|---|
| Status: | new → closed |
comment:2 by , 11 years ago
Ah, I see. Thanks for the explanation, @timgraham.
Because the User create form includes only username and password fields (no permission and staff/superuser fields), I wonder if it's worth exploring the option of changing this (e.g., user with only "can add User" permission adds a User with a username and password, is redirected back to the User list view).
comment:3 by , 11 years ago
Maybe... I didn't research when that restriction was added to see if things have changed since then.
This is expected behavior. Please see the auth documentation.