Skip to content

Commit

Permalink
allow get param if no post
Browse files Browse the repository at this point in the history
  • Loading branch information
TonisOrmisson committed Nov 6, 2017
1 parent 89b6f19 commit b1190ab
Show file tree
Hide file tree
Showing 2 changed files with 10 additions and 1 deletion.
7 changes: 6 additions & 1 deletion application/controllers/admin/useraction.php
Expand Up @@ -487,7 +487,9 @@ public function savepermissions()
public function setuserpermissions()
{
$iUserID = (int) Yii::app()->request->getPost('uid');
$aBaseUserPermissions = Permission::model()->getGlobalBasePermissions();
if(!$iUserID){
$iUserID = Yii::app()->request->getParam('uid');
}
if ($iUserID) {
//Only super admin (read) can update other user
if(Permission::model()->hasGlobalPermission('superadmin','read')) {
Expand Down Expand Up @@ -554,6 +556,9 @@ public function setusertemplates()
App()->getClientScript()->registerPackage('jquery-tablesorter');
App()->getClientScript()->registerScriptFile( App()->getConfig('adminscripts') . 'users.js');
$postuserid = (int) Yii::app()->request->getPost("uid");
if(!$postuserid){
$postuserid = Yii::app()->request->getParam('uid');
}
$oUser = User::model()->findByAttributes(array('uid' => $postuserid));
if(!$oUser) {
// @todo : review to send a 403
Expand Down
4 changes: 4 additions & 0 deletions tests/data/views/adminUsersViews.php
Expand Up @@ -10,4 +10,8 @@

['usersIndex', ['route'=>'user/sa/index']],
['modifyUser', ['route'=>'user/sa/modifyuser/uid/{UID}']],

// needs POST implementation
//['modifyUser', ['route'=>'user/sa/setuserpermissions/uid/']],
setusertemplates
];

0 comments on commit b1190ab

Please sign in to comment.