Hi. Was playing about with permissions in 2.3 - and noticed if you allow a user access to edit the customers, they have the ability to export them all via the admin customers grid.
It seems an oversight to me - as an admin user can then have your whole customer database. Would anyone have a solution I could try to disable this?
Thanks, Fred
Hi @flatairbag
Yes, That's true because at the end resource sharing is the same between whole module so the backend user who have customer access permission - can export whole the customers details as well, Because its native feature of Magento.
If you still would like to disable this export options then you will require to do customization on the top of this - that will works for you !
Hope it helps !
Hi Fred,
I can't agree more. I wonder why the customer export feature can't remain disabled by default. It's a barely used feature with such a high security risk.
We just published a free version of https://github.com/magenizr/Magenizr_Conceal for exactly your problem.
Cheers,
John