Security flaw - Default administrator registration

Hello, when registering a new user, even if it is a customer, the registration is pulling the permission as Administrator by default. As the permissions are on another screen, which the system does not require to be reviewed when registering, it can happen that a customer is mistakenly registered as a platform administrator and has access to all our customers.

We understand that this is a serious UI/UX error, and we ask that at least one (ideally all) of the following measures be taken to avoid this problem:

1 - Separate the client user registration button from the office user registration button;
2 - Make the permissions blank by default, forcing the user to select one;
3 - Force the user to go through the permissions screen, or display the permissions on the same registration screen.

Thank you.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Sugestão de Melhoria

Date

Over 2 years ago

Author

Daniel

Subscribe to post

Get notified by email when there are changes.