Repository navigation
Default Admin user should not be allowed to change its ROLE type #10931
Copy link
Copy link
Description
Activity
Server side already seems to block any changes to the system account.
if (account.getId() == Account.ACCOUNT_ID_SYSTEM) { So this would be UI improvements only to hide edit button:
cloudstack/ui/src/config/section/account.js
Line 125 in 16c60c7
api: 'updateAccount', By the way, shouldn't
cloudstack/ui/src/config/section/account.js
Line 187 in 16c60c7
api: 'disableAccount',
be calling lockAccount api instead of disableAccount.hey @fmaximus , welcome back ;) I think you are right about the api call. I also see that both blocks pass the ‘lock’ parameter. Not sure if that is a c&p feature as well, but it looks strange at least.
- added this to Apache CloudStack 4.22.0 and removed this from Apache CloudStack 4.21.0
on Aug 29, 2025 - added a commit that references this issue
on Sep 30, 2025 - linked a pull request that will close this issueserver,ui: prevent role change for default accounts #11761
on Oct 31, 2025 - moved this from Dev In Progress to ready for Review in Apache CloudStack BugFest - Issues
on Nov 3, 2025 - added a commit that references this issue
on Dec 12, 2025 - moved this from ready for Review to Done in Apache CloudStack BugFest - Issues
on Dec 16, 2025 - added a commit that references this issue
on Feb 6, 2026
Metadata
Metadata
Assignees
Type
Projects
- StatusShow more project fieldsDone
The required feature described as a wish
If the default admin user changes the role type to user role by mistake, the default admin is locked out completely
Currently, there is no option to delete the default admin account and user( which is good) , the same functionality should be extended to role type
Expected behaviour
The role type of default admin should be set to Root admin and not allowed to change by admin