On my server, the Staff members have the "Manage Roles" global permission, which they need to revoke users' ability to post in case someone starts making a stink. However, this also grants them the ability to change the per-channel permissions, which in most cases would also be fine.
The problem is that this allows any Staff member to exclude any other Staff member from channels, just by adding the other user to the per-channel permissions list and subsequently revoking their ability to see that channel. This has even let them kick Admins out of channels, since my Admins do not have the "Administrator" global permission for various reasons.
This could easily lead to abuse and I hope this is something you will address.
Iniciar sesión para dejar un comentario.