Hi. I suggest to restrict in the code a possibility to make not-autopatrolled user to be an interface-admin.
There was a lot of discussions about security risks in IA rights over tge last years and the need to give them only to the most trusted. Users that still not ready for autopatrolled for sure do not "look" trusted enough. But the technical possibilty to do this exists.
I fill this task because one of our bureacrats asked me to request this, after his experience to unintentionally give IA rights to autoconfirmed user. Thank you.
- Pick an autoconfirmed user that has no more manually given rights.
- Try to give them a local interface-admin group rights.
- Expected: it fails with proper warning.
- Got: it succeeds.
(By the way, the link above, "Read what to include in a security issue report", is broken.)