Fixed privileges in user view

This commit is contained in:
Marcin Kurczewski 2014-05-06 19:03:13 +02:00
parent e610963d4b
commit 42b8049ae5

View file

@ -33,9 +33,17 @@ class UserController
$query = 'fav:' . $user->getName();
elseif ($tab == 'delete')
Access::assert(new Privilege(Privilege::DeleteUser));
{
Access::assert(new Privilege(
Privilege::DeleteUser,
Access::getIdentity($user)));
}
elseif ($tab == 'settings')
Access::assert(new Privilege(Privilege::ChangeUserSettings));
{
Access::assert(new Privilege(
Privilege::ChangeUserSettings,
Access::getIdentity($user)));
}
elseif ($tab == 'edit' and !(new EditUserJob)->canEditAnything(Auth::getCurrentUser()))
Access::fail();