You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Brendan Abbott edited this page May 4, 2011
·
1 revision
The Members: Lock Role filter should be used as an additional security measure to
ensure that the member cannot DOM hack their own Role. This filter ensures a newly
registered member will always be of the Default Role or if updating a Member record,
the filter ensures the Role doesn't change from the Member's current role. If you
do not use the Member: Role field, you don't need this filter on your Registration
event. If you want to elevate a Member between Roles, this can be done in the backend,
or don't use this filter. Care will need to be taken that a Member is not able to
change their Role to whatever they please.