mirror of
https://github.com/pandorafms/pandorafms.git
synced 2025-07-28 08:14:38 +02:00
Fixed several problems of security. Tiquet: #3550
This commit is contained in:
parent
c8e49ef7b3
commit
36ec5ca8f1
@ -18,6 +18,14 @@ global $config;
|
|||||||
|
|
||||||
// ui_require_css_file('update_manager', 'godmode/update_manager/');
|
// ui_require_css_file('update_manager', 'godmode/update_manager/');
|
||||||
|
|
||||||
|
check_login ();
|
||||||
|
|
||||||
|
// ui_require_css_file('update_manager', 'godmode/update_manager/');
|
||||||
|
if (! check_acl ($config['id_user'], 0, "PM") && ! is_user_admin ($config['id_user'])) {
|
||||||
|
db_pandora_audit("ACL Violation", "Trying to access Setup Management");
|
||||||
|
require ("general/noaccess.php");
|
||||||
|
return;
|
||||||
|
}
|
||||||
$baseurl = ui_get_full_url(false, false, false, false);
|
$baseurl = ui_get_full_url(false, false, false, false);
|
||||||
|
|
||||||
?>
|
?>
|
||||||
|
@ -16,6 +16,14 @@
|
|||||||
|
|
||||||
global $config;
|
global $config;
|
||||||
|
|
||||||
|
check_login ();
|
||||||
|
|
||||||
|
if (! check_acl ($config['id_user'], 0, "PM") && ! is_user_admin ($config['id_user'])) {
|
||||||
|
db_pandora_audit("ACL Violation", "Trying to access Setup Management");
|
||||||
|
require ("general/noaccess.php");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
ui_require_css_file('update_manager', 'godmode/update_manager/');
|
ui_require_css_file('update_manager', 'godmode/update_manager/');
|
||||||
require_once("include/functions_update_manager.php");
|
require_once("include/functions_update_manager.php");
|
||||||
enterprise_include_once("include/functions_update_manager.php");
|
enterprise_include_once("include/functions_update_manager.php");
|
||||||
|
@ -16,9 +16,16 @@
|
|||||||
|
|
||||||
global $config;
|
global $config;
|
||||||
|
|
||||||
|
check_login ();
|
||||||
//The ajax is in
|
//The ajax is in
|
||||||
// include/ajax/update_manager.ajax.php
|
// include/ajax/update_manager.ajax.php
|
||||||
|
|
||||||
|
if (! check_acl ($config['id_user'], 0, "PM") && ! is_user_admin ($config['id_user'])) {
|
||||||
|
db_pandora_audit("ACL Violation", "Trying to access Setup Management");
|
||||||
|
require ("general/noaccess.php");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
$tab = get_parameter('tab', 'online');
|
$tab = get_parameter('tab', 'online');
|
||||||
|
|
||||||
$buttons = array(
|
$buttons = array(
|
||||||
|
@ -16,6 +16,14 @@
|
|||||||
|
|
||||||
global $config;
|
global $config;
|
||||||
|
|
||||||
|
check_login ();
|
||||||
|
|
||||||
|
if (! check_acl ($config['id_user'], 0, "PM") && ! is_user_admin ($config['id_user'])) {
|
||||||
|
db_pandora_audit("ACL Violation", "Trying to access Setup Management");
|
||||||
|
require ("general/noaccess.php");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
$action_update_url_update_manager = (bool)get_parameter(
|
$action_update_url_update_manager = (bool)get_parameter(
|
||||||
'action_update_url_update_manager', 0);
|
'action_update_url_update_manager', 0);
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user