Chronograf Viewer Role can edit InfluxDb

Why can a user i Chronograf with viewer role edit or even delete a influxdb database? i mean whats the point of being read only, when you can rease the whole datastore? Any advise on how to setup a real read-only user?