From 339053e73e0343131d148efa5b895ede505fffcc Mon Sep 17 00:00:00 2001 From: Guy Sartorelli Date: Fri, 17 Apr 2020 10:14:59 +1200 Subject: [PATCH] Fix canEdit permissions. If permissions earlier in the inheritance chain fail, we should not allow users to edit posts. If permissions earlier in the inheritance chain succeed, we should still go through the checks in this method. --- src/Model/BlogPost.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/Model/BlogPost.php b/src/Model/BlogPost.php index 77f36e4..4b2e193 100644 --- a/src/Model/BlogPost.php +++ b/src/Model/BlogPost.php @@ -564,8 +564,8 @@ class BlogPost extends Page { $member = $this->getMember($member); - if (parent::canEdit($member)) { - return true; + if (!parent::canEdit($member)) { + return false; } $parent = $this->Parent();