mirror of
https://github.com/webmin/webmin.git
synced 2026-10-01 01:40:39 +01:00
Check again if user is editable before saving
This commit is contained in:
@@ -479,6 +479,9 @@ if (%ouser) {
|
||||
$in{'chgid'} = !$access{'chgid'} if ($access{'chgid'} != 1);
|
||||
$in{'others'} = !$access{'mothers'} if ($access{'mothers'} != 1);
|
||||
|
||||
# Re-check for user validity
|
||||
&can_edit_user(\%access, \%user) || &error($text{'usave_eeditafter'});
|
||||
|
||||
# Run the pre-change command
|
||||
&set_user_envs(\%user, 'MODIFY_USER',
|
||||
$in{'passmode'} == 3 ? $in{'pass'} : "", \@sgids, $ouser);
|
||||
@@ -538,7 +541,6 @@ if (%ouser) {
|
||||
$user{'passmode'} = 4;
|
||||
}
|
||||
$user{'plainpass'} = $in{'pass'} if ($in{'passmode'} == 3);
|
||||
&can_edit_user(\%access, \%user) || &error($text{'usave_eeditafter'});
|
||||
&modify_user(\%ouser, \%user);
|
||||
|
||||
# Add, update or remove the SSH public key managed by this module.
|
||||
@@ -569,6 +571,9 @@ else {
|
||||
$config{'user_files'} =~ /\S/);
|
||||
$in{'others'} = !$access{'cothers'} if ($access{'cothers'} != 1);
|
||||
|
||||
# Check for user validity
|
||||
&can_edit_user(\%access, \%user) || &error($text{'usave_eeditafter'});
|
||||
|
||||
# Run the pre-change command
|
||||
&set_user_envs(\%user, 'CREATE_USER',
|
||||
$in{'passmode'} == 3 ? $in{'pass'} : "", \@sgids);
|
||||
@@ -612,7 +617,6 @@ else {
|
||||
# Save user details
|
||||
$user{'passmode'} = $in{'passmode'};
|
||||
$user{'plainpass'} = $in{'pass'} if ($in{'passmode'} == 3);
|
||||
&can_edit_user(\%access, \%user) || &error($text{'usave_eeditafter'});
|
||||
&create_user(\%user);
|
||||
|
||||
# Copy files into user's directory
|
||||
|
||||
Reference in New Issue
Block a user