Fix client API: only admin can add users
This commit is contained in:
parent
35019c3d39
commit
1513ff53a3
@ -42,6 +42,10 @@ switch ($action) {
|
|||||||
|
|
||||||
// action: adduser (currently unused)
|
// action: adduser (currently unused)
|
||||||
case "adduser":
|
case "adduser":
|
||||||
|
if (!$user->isAdmin) {
|
||||||
|
setError($response, "User not authorized");
|
||||||
|
break;
|
||||||
|
}
|
||||||
$login = isset($_REQUEST['login']) ? $_REQUEST['login'] : NULL;
|
$login = isset($_REQUEST['login']) ? $_REQUEST['login'] : NULL;
|
||||||
$pass = isset($_REQUEST['password']) ? $_REQUEST['password'] : NULL;
|
$pass = isset($_REQUEST['password']) ? $_REQUEST['password'] : NULL;
|
||||||
if (!empty($login) && !empty($pass)) {
|
if (!empty($login) && !empty($pass)) {
|
||||||
|
Loading…
x
Reference in New Issue
Block a user