[1.0.X] Fixed #10694: correctly check permissions in the change passw…

…ord admin. Thanks, jturnbull. Backport of r10591 from trunk.

1 parent 283442a commit f0e7dca9d1140731d673bafe5530862d7b041171 @jacobian jacobian committed Apr 18, 2009
@@ -90,7 +90,7 @@ def add_view(self, request):
}, context_instance=template.RequestContext(request))
def user_change_password(self, request, id):
- if not request.user.has_perm('auth.change_user'):
+ if not self.has_change_permission(request):
raise PermissionDenied
user = get_object_or_404(self.model, pk=id)
if request.method == 'POST':

