mirror of
https://github.com/Pathduck/gallery3.git
synced 2026-05-19 19:09:13 -04:00
Only admins can delete users.
This commit is contained in:
@@ -82,7 +82,7 @@ class Users_Controller extends REST_Controller {
|
||||
* @see REST_Controller::_delete($resource)
|
||||
*/
|
||||
public function _delete($user) {
|
||||
if (!user::active()->admin && ($user->guest || $user->id != user::active()->id)) {
|
||||
if (!user::active()->admin) {
|
||||
access::forbidden();
|
||||
}
|
||||
// Prevent CSRF
|
||||
|
||||
Reference in New Issue
Block a user