Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with
or
.
Download ZIP
Browse files

BUGFIX Disallow addition of members to groups with MemberTableField->…

…addtogroup() when the editing member doesn't have permissions on the added member

git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/cms/branches/2.4@110859 467b73ca-7a2a-4603-9d3b-597d59a354a9
  • Loading branch information...
commit 01373cf4afe48b4e4285175cbc7a58a16f196476 1 parent 51fee3f
@chillu chillu authored sminnee committed
Showing with 2 additions and 0 deletions.
  1. +2 −0  code/MemberTableField.php
View
2  code/MemberTableField.php
@@ -176,6 +176,8 @@ function addtogroup() {
$className,
sprintf('"%s" = \'%s\'', $identifierField, $data[$identifierField])
);
+
+ if($record && !$record->canEdit()) return $this->httpError('401');
}
// Fall back to creating a new record
Please sign in to comment.
Something went wrong with that request. Please try again.