mirror of
https://github.com/Part-DB/Part-DB-server.git
synced 2026-03-05 23:15:50 +01:00
Improved permission checking for certain controllers.
This commit is contained in:
@@ -131,7 +131,7 @@ class AttachmentFileController extends AbstractController
|
||||
*/
|
||||
public function attachmentsTable(Request $request, DataTableFactory $dataTableFactory, NodesListBuilder $nodesListBuilder)
|
||||
{
|
||||
$this->denyAccessUnlessGranted('read', new PartAttachment());
|
||||
$this->denyAccessUnlessGranted('@attachments.list_attachments');
|
||||
|
||||
$formRequest = clone $request;
|
||||
$formRequest->setMethod('GET');
|
||||
|
||||
Reference in New Issue
Block a user