From 3ac958ac0167d1c1989fc09e893a578e8a22f21f Mon Sep 17 00:00:00 2001 From: Eli Schwartz Date: Sun, 18 Aug 2019 03:17:05 -0400 Subject: Move permission for LIST_COMMENTS to dev/tu block In commit 3578e77ad4e9258495eed7e786b7dc3aebcf1b63 we implemented listing of comments from the account details page , but this was intended to only be available to TUs and Devs. As the comment says: "display the comment list if they're a TU/dev" The credential checking code, however, set this credential for all users, contrary to the intention of the commit. In order to preserve the ability to list a person's own comments, also declare the allowed uids based on the profile being viewed. --- web/html/account.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'web/html') diff --git a/web/html/account.php b/web/html/account.php index 9695c9b7..1d59e9c9 100644 --- a/web/html/account.php +++ b/web/html/account.php @@ -167,7 +167,7 @@ if (isset($_COOKIE["AURSID"])) { } } elseif ($action == "ListComments") { - if (has_credential(CRED_ACCOUNT_LIST_COMMENTS)) { + if (has_credential(CRED_ACCOUNT_LIST_COMMENTS, array($row["ID"]))) { # display the comment list if they're a TU/dev $total_comment_count = account_comments_count($row["ID"]); -- cgit v1.2.3-24-g4f1b