Skip to content

Commit eb73ef6

Browse files
committed
[#405] Check access to settings
1 parent a5c69da commit eb73ef6

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

rvd_front.pl

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1287,6 +1287,13 @@ sub manage_machine {
12871287
sub settings_machine {
12881288
my $c = shift;
12891289
my ($domain) = _search_requested_machine($c);
1290+
1291+
return access_denied($c) if !$domain;
1292+
1293+
return access_denied($c)
1294+
unless $USER->is_admin
1295+
|| $domain->id_owner == $USER->id;
1296+
12901297
return $c->render("Domain not found") if !$domain;
12911298

12921299
$c->stash(domain => $domain);

0 commit comments

Comments
 (0)