[Rt-commit] r13636 - in rt/3.8/trunk: .

sartak at bestpractical.com sartak at bestpractical.com
Thu Jun 26 20:08:35 EDT 2008


Author: sartak
Date: Thu Jun 26 20:08:33 2008
New Revision: 13636

Modified:
   rt/3.8/trunk/   (props changed)
   rt/3.8/trunk/lib/RT/SharedSetting.pm

Log:
 r63281 at onn:  sartak | 2008-06-26 17:50:02 -0400
 Whoops, forgot to check CurrentUserCanSee in SharedSetting->Load


Modified: rt/3.8/trunk/lib/RT/SharedSetting.pm
==============================================================================
--- rt/3.8/trunk/lib/RT/SharedSetting.pm	(original)
+++ rt/3.8/trunk/lib/RT/SharedSetting.pm	Thu Jun 26 20:08:33 2008
@@ -106,6 +106,10 @@
             $self->{'Id'} = $self->{'Attribute'}->Id;
             $self->{'Privacy'} = $privacy;
             $self->PostLoad();
+
+            return (0, $self->loc("Permission denied"))
+                unless $self->CurrentUserCanSee;
+
             return (1, $self->loc("Loaded [_1] [_2]", $self->ObjectName, $self->Name));
         } else {
             $RT::Logger->error("Could not load attribute " . $id


More information about the Rt-commit mailing list