Validates global permission at the AccessControl level

Changes error response code on invalid permission
This commit is contained in:
Vlad
2017-08-20 12:27:24 -04:00
parent 1b756ef0b2
commit 78429d8f91
2 changed files with 7 additions and 11 deletions

View File

@@ -93,6 +93,7 @@ class AccessControl {
}
function validatePermission($permission) {
if($permission === self::NO_ACCESS_RESTRICTION) return true;
if(empty($this->permissions[$permission])) return false;
$permitted_roles = array_intersect(
$this->user_roles,