Fix for bug 291391: allows users to rerequest set flags even if they don't have the privilege to set them; r=lpsolit; a=myk
git-svn-id: svn://10.0.0.236/trunk@172591 18797224-902f-48f8-a5cc-f745e15eee43
This commit is contained in:
@@ -320,9 +320,9 @@ sub validate {
|
||||
# - The flag is unchanged
|
||||
next if ($status eq $flag->{status});
|
||||
|
||||
# - User in the $request_gid group can clear pending requests
|
||||
next if ($status eq 'X'
|
||||
&& $flag->{status} eq '?'
|
||||
# - User in the $request_gid group can clear pending requests and set flags
|
||||
# and can rerequest set flags.
|
||||
next if (($status eq 'X' || $status eq '?')
|
||||
&& (!$flag->{type}->{request_gid}
|
||||
|| $user->in_group(&::GroupIdToName($flag->{type}->{request_gid}))));
|
||||
|
||||
|
||||
@@ -442,12 +442,10 @@
|
||||
[% title = "Flag Modification Denied" %]
|
||||
You tried to [% IF status == "+" %] grant [% ELSIF status == "-" %] deny
|
||||
[% ELSIF status == "X" %] clear [% ELSE %] request [% END %]
|
||||
<code>[% name FILTER html %]</code>
|
||||
[% IF status == "?" && old_status != "X" %], but this flag is already
|
||||
set[% END %].
|
||||
Only a sufficiently empowered user [% IF status == "X" %] or the user who
|
||||
set <code>[% name FILTER html %][% old_status FILTER html %]</code> in
|
||||
the first place [% END %] can make this change.
|
||||
<code>[% name FILTER html %]
|
||||
[% IF status == "X" %][% old_status FILTER html %][% END %]</code>.
|
||||
|
||||
Only a sufficiently empowered user can make this change.
|
||||
|
||||
[% ELSIF error == "format_not_found" %]
|
||||
[% title = "Format Not Found" %]
|
||||
|
||||
Reference in New Issue
Block a user