mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 14:05:37 +02:00
BUGFIX Don't lowercase permission codes contained in $allowed_actions in RequestHandler->checkAccessAction(). Permission checks are case sensitive.
git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/sapphire/trunk@86085 467b73ca-7a2a-4603-9d3b-597d59a354a9
This commit is contained in:
parent
e9df16ba5a
commit
3f751a2cb8
@ -193,9 +193,11 @@ class RequestHandler extends ViewableData {
|
||||
}
|
||||
|
||||
if($allowedActions) {
|
||||
// convert all keys and values to lowercase for easier comparison (only if not set as boolean)
|
||||
// Convert all keys and values to lowercase for easier comparison.
|
||||
// Exclude values set as booleans, or permission codes (permission checks are case sensitive)
|
||||
foreach($allowedActions as $key => $value) {
|
||||
$newAllowedActions[strtolower($key)] = (is_bool($value)) ? $value : strtolower($value);
|
||||
if(is_numeric($key) || is_bool($value)) $value = strtolower($value);
|
||||
$newAllowedActions[strtolower($key)] = $value;
|
||||
}
|
||||
$allowedActions = $newAllowedActions;
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user