unprivileged users can undelete zones

Started by ddorsch, June 11, 2007, 03:10:00 AM

Previous topic - Next topic

ddorsch

Hi Matt,

just tested that:
A deleted zone has a link "undelete" in the zone log. Any User of this or above groups can hit it and the zone is reactivated. Even if the User has no permission to delete or create zones (which is default at our install).

I think this is not as it should.

sincerely,
Dorothea
<°(((><

matt

Restoring a zone is not deleting or creating. But perhaps if the user does not have the permission to delete, they also should not have the permission to restore. I would say this qualifies as a bug and I've added it to the TODO list.