XPressME Integration Kit

Trac

Changeset 510 for trunk


Ignore:
Timestamp:
Feb 5, 2010, 10:55:05 AM (15 years ago)
Author:
toemon
Message:

ブロックの配置権限をもたせたユーザがDB接続情報を見ることができてしまうバグを修正 Fixes #283

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/xpressme_integration_kit/admin/index.php

    r507 r510  
    505505function xpress_config_from_xoops_view($is_report = false) 
    506506{ 
    507         global $xoopsUserIsAdmin; 
    508  
     507        global $xoopsUserIsAdmin,$xoopsUser; 
     508 
     509        $user_groups = $xoopsUser->_groups; 
     510        $is_admin_group = in_array('1',$user_groups); 
     511         
    509512        require_once dirname(dirname( __FILE__ )).'/class/config_from_xoops.class.php' ; 
    510513        $xoops_config = new ConfigFromXoops; 
     
    516519                echo "<fieldset><legend style='font-weight: bold; color: #900;'>" . _AM_XP2_XOOPS_CONFIG_INFO . "</legend>"; 
    517520                echo "<div style='padding: 8px;'>"; 
    518                 if ($xoopsUserIsAdmin){ 
     521                if ($xoopsUserIsAdmin && $is_admin_group){ 
    519522                        xpress_config_nomal_view(); 
    520523                } else { 
Note: See TracChangeset for help on using the changeset viewer.