Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2007-05-14 11:10:37

jakob
Admin
From: Germany
Registered: 2005-01-20
Posts: 5,120
Website GitHub

privs for change_email?

A user logged in as staff writer is presented with a change email form but after clicking submit receives a “restricted area” notice.

I’m working on a recent dev version (normal branch) but I have done a diff compare of txp_admin.php and admin_config.php with the files from a fresh download of 4.0.4 and see no noteworthy differences.

function change_email() in txp_admin.php requires the privs “admin.edit” which staffwriter’s don’t have. Commenting out the line // require_privs('admin.edit'); solves the problem. Does that have any other repercussions?

jakob


TXP Builders – finely-crafted code, design and txp

Offline

#2 2007-05-14 16:44:43

ruud
Developer Emeritus
From: a galaxy far far away
Registered: 2006-06-04
Posts: 5,068
Website

Re: privs for change_email?

The ‘change_email’ function only allows you to change your own email address, so there’s no harm in opening that for all users. Besides, it doesn’t make much sense to show an option to change your email address that doesn’t work :)

Fixed in revision 2345

PS. I’m surprised that no-one noticed this before. Thanks for pointing it out.

Last edited by ruud (2007-05-14 17:26:41)

Offline

#3 2007-05-14 19:42:03

jakob
Admin
From: Germany
Registered: 2005-01-20
Posts: 5,120
Website GitHub

Re: privs for change_email?

ruud, thanks for making the change. I was surprised too, that no-one saw that before.

Congratulations BTW on joining the dev crew!


TXP Builders – finely-crafted code, design and txp

Offline

Board footer

Powered by FluxBB