Permissions not working in Groupshare 2017

Hi

 

I created a Role in GS 2017 without ANY permission. It looks like when I log in to GS with user having only this role, I am able to go to Users section, and I see organizations. 

Is it a bug ?

Moreover, in GS 2015 API it was possible to create user without any role. We heavily used that since our user-creating code was separate from granting-permission one. Now it is impossible to use API in an old way. Why it changed ? Can it be restored ?

If empty role would really work as empty role (especially organization are not visible), then it would be sufficient for us, since we can use that role for creation.

 

Regards