Skip to content
Browse files

BUGFIX Disallow addition of members to groups with MemberTableField->…

…addtogroup() when the editing member doesn't have permissions on the added member (from r110859)

git-svn-id: svn://svn.silverstripe.com/silverstripe/open/modules/cms/trunk@112797 467b73ca-7a2a-4603-9d3b-597d59a354a9
  • Loading branch information...
1 parent ad5a8e0 commit 185e30a7507029c78b11f1b014e9f2ff3104198a @sminnee sminnee committed Oct 19, 2010
Showing with 2 additions and 0 deletions.
  1. +2 −0 code/MemberTableField.php
View
2 code/MemberTableField.php
@@ -177,6 +177,8 @@ function addtogroup() {
$className,
sprintf('"%s" = \'%s\'', $identifierField, $data[$identifierField])
);
+
+ if($record && !$record->canEdit()) return $this->httpError('401');
}
// Fall back to creating a new record

0 comments on commit 185e30a

Please sign in to comment.
Something went wrong with that request. Please try again.