Issue 788: The accounts in Administrator group can remove itself also other accouts
Status:  New
Owner: ----
Reported by luo.fish...@gmail.com, Nov 30, 2010
Affected Version:2.1.6-rc1

What steps will reproduce the problem?
1.enter into the admin->Groups->Administrators
2.select myself and other admins
3.click "Delete" 

What is the expected output? What do you see instead?
Also if I am not a Administrator, I also can remove others in the group visible to me.
Maybe just admins can have this rights.

Jan 12, 2011
#1 mogulgu...@gmail.com
You describe 2 separate (but related) issues.

How do you suggest that your first complaint be addressed?  Who would control adding/deleting users from the Administrators group?  I was going to suggest that you change the owner of the Administrators group to another group, say Administrators-Owners, but that does not seem to solve the problem since Administrators are all powerful.  Perhaps this is the one are where Administrators privileges should be limited?  What if Gerrit limited Administrators from modifying the Administrators group, or the group which owns it, if the are not in the owner group?  This might give finer control over things (or it could just be way too complicated then)

As for the second problem that you mention, I believe that it can be addressed by the group's "owner group", which controls who can modify the group.  So, you should assign ownership of your groups to the Administrators group if you do not want people in a (non administrators) group to be able to modify them.
Jan 24, 2011
#2 luo.fish...@gmail.com
Maybe my words have confused you, what I mean is that whether I am a administrator, I can add or remove anyone into groups visible to me.
But in my mind,  I get used to that only administrators have this rights. So I post this bug. Nothing else.