1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Not a Bug User 1 can see all admin sections even if the permission is off

Discussion in 'Resolved Bug Reports' started by rellect, Jan 15, 2014.

  1. rellect

    rellect Well-Known Member

    I've noticed that user id 1 can see all admin sections, the admin permissions does not apply.
    If this is by design I think it's need a change as not always user1 need access to all sections, for example if he has a tech man that manage his site for him. In this case I don't want user1 to have access into sections where he can change something that shouldn't be changed.
  2. xf_phantom

    xf_phantom Well-Known Member

    I bet he's still superadmin!

    Check your config.php;) and remove him from the superadmins array
  3. Brogan

    Brogan XenForo Moderator Staff Member


    A Super Administrator always has all permissions in the ACP.
  4. rellect

    rellect Well-Known Member

    I actually thought about it and tried that, but it didn't "fixed" that.
    What I did was to remove the superAdmins line from the config.
    But now I see that if I leave this line but set another userid, user1 indeed don't see what he shouldn't see.
  5. Brogan

    Brogan XenForo Moderator Staff Member

    Yes, you need to enter the user IDs of only those users who are super admins, comma separated.

    If you remove the entry altogether there will be no super admins.
  6. rellect

    rellect Well-Known Member

    In this case, why user1 can see all sections if he is not a super admin?
  7. Mike

    Mike XenForo Developer Staff Member

    Actually, if you remove the line all together, it will use the default value which makes 1 the super admin (this can be seen in the control panel).

    You can use an empty value though.
    Brogan likes this.
  8. Brogan

    Brogan XenForo Moderator Staff Member

    Aha, good to know, thanks Mike.
  9. xf_phantom

    xf_phantom Well-Known Member

    But wouldn't it make more sense, to change the default config array and remove the userid 1 from the default superadmins array?

    Stricly speaking, if it's not in the config.php then IMO nobody should be superadmin.
    This way it's IMO very confusing.

    Edit: http://xenforo.com/community/threads/remove-the-superadmin-user-in-default-config.66685/
    Last edited: Jan 15, 2014
    Mouth likes this.

Share This Page