<p>They already have to be an administrator to grant or revoke roles - all actions in the <code>user_roles</code> controller are subject to the <code>require_administrator</code> filter.</p>
<p>I don't see any particular reason to stop an administrator acting on their own account - maybe stop them removing their own administrator role but I don't see any need for anything more than that.</p>
<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">—<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/openstreetmap/openstreetmap-website/issues/1697#issuecomment-349778095">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/ABWnLR1S7KaRPUADNxCb_DZQHuHxfnPhks5s9wTygaJpZM4Q4lPq">mute the thread</a>.<img alt="" height="1" src="https://github.com/notifications/beacon/ABWnLZ7NzZRZkkNbhf54fq5pPgE7CvKMks5s9wTygaJpZM4Q4lPq.gif" width="1" /></p>
<div itemscope itemtype="http://schema.org/EmailMessage">
<div itemprop="action" itemscope itemtype="http://schema.org/ViewAction">
<link itemprop="url" href="https://github.com/openstreetmap/openstreetmap-website/issues/1697#issuecomment-349778095"></link>
<meta itemprop="name" content="View Issue"></meta>
</div>
<meta itemprop="description" content="View this Issue on GitHub"></meta>
</div>
<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/openstreetmap/openstreetmap-website","title":"openstreetmap/openstreetmap-website","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/openstreetmap/openstreetmap-website"}},"updates":{"snippets":[{"icon":"PERSON","message":"@tomhughes in #1697: They already have to be an administrator to grant or revoke roles - all actions in the `user_roles` controller are subject to the `require_administrator` filter.\r\n\r\nI don't see any particular reason to stop an administrator acting on their own account - maybe stop them removing their own administrator role but I don't see any need for anything more than that."}],"action":{"name":"View Issue","url":"https://github.com/openstreetmap/openstreetmap-website/issues/1697#issuecomment-349778095"}}}</script>