First of all, I will like to thank the developers of the role plugins of elgg. Am sure many elgg users know the importance of these plugins. I have tried the roles and roles moderators plugins and that wonderful roles_ui by hypejunction (you guys rock).
Unfortunately, a very important feature that should have been implemented to perfect these plugins have been ignored, that is, preventing admins from performing admin actions on fellow admin users, especially, the default admin user account.
I will like to think that this particular feature is important for any site just like any other core security feature and should be implemented into core.
All that being said, I'll appreciate any temporary fix if anyone has an idea or code for making admins immune to admin actions such as delete, ban, login as. Thanks!
info@elgg.org
Security issues should be reported to security@elgg.org!
©2014 the Elgg Foundation
Elgg is a registered trademark of Thematic Networks.
Cover image by Raül Utrera is used under Creative Commons license.
Icons by Flaticon and FontAwesome.
- ihayredinov@ihayredinov

ihayredinov - 1 like
You must log in to post replies.Don't give admin rights to users you don't trust. Create a semi-admin role if you have to.