diff options
| author | Tim Almdal <tnalmdal@shaw.ca> | 2009-08-17 19:52:40 -0700 |
|---|---|---|
| committer | Tim Almdal <tnalmdal@shaw.ca> | 2009-08-17 19:52:40 -0700 |
| commit | 82edd2a37bde6f42f5ff69c1363c5dbeb3cec599 (patch) | |
| tree | 3a37d7bdd673a516aef21a104f1aff7e4baad3cf /modules/organize/controllers | |
| parent | 848c5439b3c17da58c2cfd94ccc62193a3fe7bd2 (diff) | |
This patch adds some security to the organize dialog.
1) If images are dragged from the content pane and dropped on a branch in the
tree that the user only has view priviledges, then the drop is cancelled
and the images are reverted.
2) The user cannot click on a branch, to which they only have view priviledges,
the content pane does not change to the new album
Diffstat (limited to 'modules/organize/controllers')
| -rw-r--r-- | modules/organize/controllers/organize.php | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/modules/organize/controllers/organize.php b/modules/organize/controllers/organize.php index 7d6b651e..76a22b73 100644 --- a/modules/organize/controllers/organize.php +++ b/modules/organize/controllers/organize.php @@ -118,6 +118,7 @@ class Organize_Controller extends Controller { $v->album = $item; $keys = array_keys($parents); $v->selected = end($keys) == $item->id; + $v->can_edit= access::can("edit", $item); $v->children = array(); $v->album_icon = "gBranchEmpty"; |
