Granting “delete users” capability breaks UM’s “Login as this user”
-
I am the webmaster / developer for a site for a non-profit group that has annual memberships. It is a single site WordPress configuration (i.e. not multi-site).
We use Ultimate Member to handle the membership. We use many roles to control access and capabilities. Most accounts have the role of “Member”. One other role I created is “Membership-Chair”. Anyone with that role is allowed to approve and edit “Member” accounts. As well, they can delete accounts having the role of “Lapsed Member”.
As “Administrator” I was always able to “Login as this user” for any account on the system, including folk with the “Membership-Chair” role. A few months ago I noticed that the “Login as this user” option was no longer available to me for a “Membership-Chair” account.
I figured out what may have been the issue: PublishPress Capabilities showed that the “Membership-Chair” role had both of the WordPress “delete users” and “remove users” capabilities included in their role.
I found out that when “delete users” rights are allowed, I lose the “Login as this user” option on their account. But if I take away the “delete user” capability, the “Membership-Chair” loses the ability to delete users from the back-end admin “Users” screens.
Adding or removing “remove users” rights via PublishPress makes no difference to UM “Login as this user” or to having back-end delete rights.
Furthermore, I found out that as long as “Can delete other member accounts?” is set in the UM role definition for “Membership-Chair”, they can delete accounts from the UM profile screens even if neither one of “delete users” or “remove users” are granted via PublishPress.
I don’t need to let Membership-Chair delete accounts via admin back-end, so my fix is to (1) make sure the Membership-Chair role “Can delete other member accounts?” is set in the UM role and (2) both “delete users” and “remove users” are NOT granted via PublishPress.
However, and here is the “support request” part, you may want to look into why granting “delete users” wordpress capability on a role breaks UM’s “Login as this user”.
FYI WordPress 6.1.1 running with Ultimate Member Version 2.5.4 and PublishPress Capabilities Version 2.7.0
- The topic ‘Granting “delete users” capability breaks UM’s “Login as this user”’ is closed to new replies.