Can't remove o modify user's roles

Hi,

ion OJS 3.4.0.8, with my site administrator access I can’t manage users with Journal manager role. If I try I get the following popup:

You do not have sufficient permissions to administer this user. In order to administer a user, you must either be site administrator, or administer all contexts that this user is enrolled in.

Do you confirm that only site administrator can see the following menu?

Any suggestion?

Otherwise, can I modify user role on DB?

Thank you.

Hi @Enzo,

Is it possible that the other user is also a site administrator?

Regards,
Alec Smecher
Public Knowledge Project Team

I noticed that the three users I wanted modify are registered in user_user_groups table with 1 in user_group_id column. Modifing it to a different number (16) their rule is changed, but I can’t explain why I had 4 site administrators.

Enzo

Hi @Enzo,

This might be a security problem, past or present. I’d suggest reviewing any site admins and journal managers via the database, and changing any remaining accounts’ passwords. Your installation is a few versions out of date, so I would also recommend upgrading.

Regards,
Alec Smecher
Public Knowledge Project Team

@asmecher Does this mean that it is not recommended (in OJS) to have more than one user with site admin privileges?

Kind regards,
Maria

Hi @mirkh,

There is no problem with having multiple site admin accounts – but they should be carefully protected with safe passwords.

Regards,
Alec Smecher
Public Knowledge Project Team

Ok, great, thanks! Have a good weekend!

This topic was automatically closed after 9 days. New replies are no longer allowed.