Contents
Safety guardrails - Plugixa Advanced User Role Editor
Editing roles is how sites get broken, so the plugin enforces a set of rules on every change. They are checked on the server, not only on the screen, and they apply the same way to a save, an import, a restore and a bulk move of people.
Most of them are not settings. The two that can be relaxed are marked.
Nothing is saved until you review it
Edits to roles and people do not save as you make them. They collect in a bar at the bottom of the screen marked Unsaved changes, which shows how many people are affected and offers Discard and Review and save.
Review and save opens Review changes: every change in words, grouped by role and person. The review is of exactly what will be saved. If any rule below is broken, the review says This cannot be saved with the reason, and the bar is marked Cannot be saved as it is.
A save is all or nothing. If one part is refused, none of it is written.
A restore point first
A restore point is taken before every save. The review says so (“A restore point is saved first, so this can be undone.”) and the notice after saving has an Undo button. See History and restore.
The rules
Administrator is locked by default
The Administrator role cannot be changed until you allow it.
Administrator is locked, so nobody changes the role the site depends on by accident. Turn on editing Administrator in Settings first.
Can be changed: Settings -> Roles and permissions -> Allow editing the Administrator role. Off by default.
The Administrator role can never be deleted, whatever the setting:
The “administrator” role cannot be deleted. WordPress needs it, and a site without one cannot be recovered from this screen.
You cannot lock yourself out
A change that would remove your own access to the editor is refused. The plugin works out what you would be able to do after the whole change, so two edits that are each safe but together lock you out are caught, and so is a change to your own account.
That change would remove your own access to this editor, and you would not be able to undo it here. Grant the capability to another role you hold first, or make the change from an administrator account.
The site must keep an administrator
The last account with the Administrator role cannot lose it.
This is the only administrator on the site. Give another account the administrator role first, then change this one.
This change would leave the site with no administrator. Give another account the administrator role first.
Moving everybody off Administrator in one go is refused too:
Moving everyone off the Administrator role in one go could leave the site with nobody able to run it. Change administrators one at a time on the People screen.
On multisite this rule does not apply. See Multisite.
A person needs at least one role
A user needs at least one role. To remove their access, delete the account or give them a role with nothing in it.
Deleting a role that people still hold is refused until you choose where they go: “3 users still hold this role. Choose a role to move them to first.”
You cannot give what you do not hold
You can only grant a permission you hold yourself, and only hand out a role if you hold everything in it. Without this rule, access to the editor would be access to everything.
You cannot grant “install_plugins”, because you do not hold it yourself.
The same applies to taking away. Otherwise somebody with limited access could strip permissions from everyone above them.
You cannot revoke “manage_options”, because you do not hold it yourself.
A permission you add by name yourself is the exception: nobody holds a brand-new name, so a new, harmless one can be given out. Names that look like powerful permissions are refused when you add them.
You cannot change an account that holds more than you
This account holds permissions you do not have yourself, so you cannot change it. Ask someone who holds them.
On the person’s page the controls are greyed out with a shorter version of the same message.
Full-control permissions need typing to confirm
Some permissions amount to full control of the site: installing, updating or editing plugins and themes, changing site settings, and creating, editing, promoting or deleting users, among others. Granting one to a role or a person, or giving a person a role that contains one, is called out in the review under This hands over control of the site, with what each one allows.
To save, you type the name shown in the box - the role or the person. The server checks it as well, so the step cannot be skipped by anything talking to the site directly:
Some of these changes hand over control of the site. Confirm each of them before saving.
Can be changed: Settings -> Safety -> Type the name to confirm a permission that hands over the site. On by default. With it off, the warning is still shown; only the typing is dropped.
Less dangerous but still powerful permissions are listed under This grants some powerful permissions and need no typing.
A change on top of somebody else’s is refused
If another person changed the same role or account after you opened the screen:
Editor was changed by someone else after you opened this screen. Reload to see their change, then make yours again.
Redirects stay on this site
A redirect to an address on another host is refused when you save it, and checked again when it is used. See Login redirects.
Clean-up will not break an installed plugin
Remove from all roles is only offered for permissions nothing on the site claims. It is refused for the plugin’s own permissions, for one a plugin still registers, and for one that looks like it belongs to an installed plugin:
“manage_woocommerce” looks like it belongs to WooCommerce, which is installed on this site, so it is not removed from every role at once. If you are sure it is unused, remove it from each role separately.
Access to the editor is never handed out by default
On activation only Administrator can use the editor. Other roles get access only when you tick them under Settings -> Who can use this editor, and that access covers looking at and changing roles. It does not include changing people or these settings. See Settings.
The way back in
The rules above stop you locking yourself out. They cannot stop every case: a second administrator can remove the first one’s role. For that there is a recovery link, created from the command line:
wp plugixa-aure rescue <user>
<user> is a user ID, login or email. The command prints a link that:
- is valid for 15 minutes;
- works once;
- works only while signed in as that user, so a leaked link alone grants nothing;
- gives the account the Administrator role;
- is recorded in History like any other change.
It cannot be switched off from Settings. The messages you may meet when opening a link are listed in Troubleshooting.
What to do next
- See what a refused save looks like in Troubleshooting.
- Adjust the two optional rules in Settings.
- Find risky roles that already exist with Health check.