[wp-trac] [WordPress Trac] #43251: editable_roles filter doesn't exclude role on multisite

WordPress Trac noreply at wordpress.org
Wed Feb 7 19:15:55 UTC 2018


#43251: editable_roles filter doesn't exclude role on multisite
--------------------------------+-----------------------------
 Reporter:  eArtboard           |      Owner:
     Type:  defect (bug)        |     Status:  new
 Priority:  normal              |  Milestone:  Awaiting Review
Component:  Networks and Sites  |    Version:  4.9.4
 Severity:  normal              |   Keywords:
  Focuses:  multisite           |
--------------------------------+-----------------------------
 On a multisite installation I am trying to exclude a role using
 editable_roles filter.

 The role is removed from the dropdown but if I change the role value in
 the DOM using the inspector I can successfully add the excluded role.

 This happens only on multisite installations. On single installations if I
 try to add an excluded role I get the message “Sorry, you are not allowed
 to give users that role.”

 '''How to reproduce the issue:'''

 1. Unset a role using editable_roles filter.
 2. Login with any role that has the capability create_user.
 3. Add a new user changing any role value with the excluded role (using
 inspector).

--
Ticket URL: <https://core.trac.wordpress.org/ticket/43251>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list