mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 12:05:37 +00:00
BUGFIX: Don't let non ADMINs with permission-editing rights assign themselves ADMIN permissions. (from r89805)
git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/sapphire/branches/2.4@96718 467b73ca-7a2a-4603-9d3b-597d59a354a9
This commit is contained in:
parent
ad20ff2ac0
commit
150457f8a2
@ -533,6 +533,9 @@ class Permission extends DataObject {
|
||||
);
|
||||
}
|
||||
|
||||
// Don't let people hijack ADMIN rights
|
||||
if(!Permission::check("ADMIN")) unset($allCodes['ADMIN']);
|
||||
|
||||
ksort($allCodes);
|
||||
|
||||
foreach($allCodes as $category => $permissions) {
|
||||
|
Loading…
x
Reference in New Issue
Block a user