Roles without admin/ban powers can still ban if above other admin roles
I know the title is a little confusing, but I couldn't figure out how to title it. I will explain below.
Pretty much if user 1 and user 2 both have admin roles (with the administrator perm) then user 1 has a higher role (with NO PERMISSIONS at all) user 1 will still have the ability to perform administrator actions on user 2.
Why is this an issue? Sometimes you'd want to have a hoisted role (say a "now live" role) that is at the top of your server list but without any special abilities. Well with this bug(?)/issue that role that has no abilities now has the ability to ban/kick or remove roles from someone they shouldn't be able to in the first place.
4
Please sign in to leave a comment.
Comments
0 comments