News:

CPG Release 1.6.29
During HTML5 upload, keep pseudo blank code 200 messages from triggering error condition
added Russian language
correct failure to use theme menu icons in album manager
minor vulnerabilities mitigation

Main Menu

non-admin user, not in admin mode without personal gallery

Started by Tranz, March 27, 2005, 01:29:24 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Nibbler

OK, change the permission checks to
if (!(GALLERY_ADMIN_MODE || $CURRENT_PIC['category'] == FIRST_USER_CAT + USER_ID || ($CONFIG['users_can_edit_pics'] && $CURRENT_PIC['owner_id'] == USER_ID)) || !USER_ID) cpg_die(ERROR, $lang_errors['access_denied'], __FILE__, __LINE__);


and move the pageheader($title) call down to just before here:

$thumb_url = get_pic_url($CURRENT_PIC, 'thumb');

That should sort it.

Tranz

The problem with anonymous access has been resolved.

The non-admin user got this message after clicking the button to edit:
You don't have permission to access this page.

Nibbler


Tranz

Donnoman updated the cpg-contrib gallery with the file and it worked fine as far as editing. Thanks. :)

But I am denied access as the user when trying the buttons for crop/rotate and delete.


Tranz