From c3928be7f8631fc0ad6df4cfd8e62ed435fe7adf Mon Sep 17 00:00:00 2001 From: dogmatic Date: Fri, 11 Jun 2010 12:36:02 +0200 Subject: [PATCH] stop non admins from using admin (temp fix) --- app_controller.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/app_controller.php b/app_controller.php index 9fa0ee158..5295311f6 100644 --- a/app_controller.php +++ b/app_controller.php @@ -101,6 +101,10 @@ function beforeFilter() { } } + if((isset($this->params['admin']) && $this->params['admin']) && $this->params['action'] != 'admin_login' && $this->Session->read('Auth.User.group_id') != 1){ + $this->redirect(array('admin' => 1, 'plugin' => 'management', 'controller' => 'users', 'action' => 'login')); + } + if (isset($this->data['PaginationOptions']['pagination_limit'])) { $this->Infinitas->changePaginationLimit( $this->data['PaginationOptions'], $this->params ); }