Author Topic: Super User is between customers... crazy!!  (Read 434 times)

assolollo

  • Beginner
  • *
  • Posts: 12
  • A beginner
Super User is between customers... crazy!!
« on: April 04, 2017, 11:20:54 am »
Hi,
why Super User account is between customers? I created an e-commerce for my client, but He can to delete my account Super User...... crazy!!!!!!!

How can I prevent the cancellation?

Thanks

Virtuemart 3.2.0

jenkinhill

  • UK Web Developer & Consultant
  • Global Moderator
  • Super Hero
  • *
  • Posts: 26315
  • Always on vacation
    • Jenkin Hill Internet
Re: Super User is between customers... crazy!!
« Reply #1 on: April 04, 2017, 12:21:26 pm »
It's Joomla, not VirtueMart that this relates to, as it applies to any Joomla installation. Simply any super user in Joomla can create, block or delete any other super user. AFAIK you cannot prevent it, but you could ask on the Joomla forum. 

Kelvyn

Jenkin Hill Internet,
Keswick, Lake District

Unsolicited PMs/emails will be ignored.

Please mention your VirtueMart, Joomla and PHP versions when asking a question in this forum

Currently using VM3.2.4 on Joomla 3.8 PHP 7.0.23

Testing VM3.2.5.9653 on J!3.8

assolollo

  • Beginner
  • *
  • Posts: 12
  • A beginner
Re: Super User is between customers... crazy!!
« Reply #2 on: April 04, 2017, 16:24:20 pm »
With permissions of Joomla, I can decide to deny access to user management, but no in Virtuemart because all users are customers!!!!

Milbo

  • Virtuemart Projectleader
  • Administrator
  • Super Hero
  • *
  • Posts: 9336
  • VM3.2 Cached and Optimized
    • VM3 Extensions
  • VirtueMart Version: VirtueMart 3 on joomla 3
Re: Super User is between customers... crazy!!
« Reply #3 on: April 05, 2017, 09:45:00 am »
Please list here the Access rights of Virtuemart and then you will notice it yourself.

At the moment, I think you do not even know that VM has more than 100 permission rules. All of them are based on joomla.

When your customer should not be allowed to have full control over HIS store, the write this in your customer contract and make him Administrator!

common, that is really, basic shit. It is anywhere the same. Windows, Linux, Mac, wordpress, joomla,... as Superuser, root, Mainadministrator, "theguywhoisresponsibleforanyshit" you are allowed todo anything. Try to delete yourself as superuser, upss, that does not work, so,.. tell me how to delete a superuser if not another superuser is doing it.

So rethink your logic :-) You will notice that your logic is atm not consistent, yet.
I should fix your bug, please support the VirtueMart project and become a member
______________________________________
Extensions approved by the core team: http://extensions.virtuemart.net/

assolollo

  • Beginner
  • *
  • Posts: 12
  • A beginner
Re: Super User is between customers... crazy!!
« Reply #4 on: April 05, 2017, 19:20:06 pm »
Milbo, thanks for your truthful answer.

According to my logic, I gave "Manager" permission rule to my client which will administer the shop and I assigned him different allow for each function of VM.

Is there a better solution? Thanks.

Milbo

  • Virtuemart Projectleader
  • Administrator
  • Super Hero
  • *
  • Posts: 9336
  • VM3.2 Cached and Optimized
    • VM3 Extensions
  • VirtueMart Version: VirtueMart 3 on joomla 3
Re: Super User is between customers... crazy!!
« Reply #5 on: April 05, 2017, 19:29:41 pm »
It is the correct solution. The thing is, when your manager is allowed to edit users, he is also allowed to edit the superuser. But as far as I know, he cannot remove the superadmin status. You may test this.

The store information is vendor information. So it makes sense, that managers are allowed to change the store information, and the store is often bind to the superadministrator.
I should fix your bug, please support the VirtueMart project and become a member
______________________________________
Extensions approved by the core team: http://extensions.virtuemart.net/

assolollo

  • Beginner
  • *
  • Posts: 12
  • A beginner
Re: Super User is between customers... crazy!!
« Reply #6 on: April 06, 2017, 19:17:47 pm »
Yes, with this configuration, my client can to delete Super User account!!!!!!!

(I had to remove the Delete button in administrator/components/com_virtuemart/views/user/view.html.php  :( :( :( :( :( )