32d14f493b
Any user with the `shiftentry_edit_angeltype_supporter` privilege was able to sign up any users of the correct angeltype to any shift that they could sign up themselves because the shift entry controller only checks for the global privilege an not the fact that the user is indeed supporter for the angeltype in question. |
||
---|---|---|
.. | ||
angeltypes_controller.php | ||
event_config_controller.php | ||
rooms_controller.php | ||
shift_entries_controller.php | ||
shifts_controller.php | ||
shifttypes_controller.php | ||
user_angeltypes_controller.php | ||
user_driver_licenses_controller.php | ||
users_controller.php |