Skip to content
GitLab
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • mahara mahara
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1
    • Issues 1
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 1
    • Merge requests 1
  • Deployments
    • Deployments
    • Releases
  • Packages and registries
    • Packages and registries
    • Container Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • Repository
  • Wiki
    • Wiki
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • maharamahara
  • maharamahara
  • Repository
Switch branch/tag
  • mahara
  • htdocs
  • auth
  • user.php
Find file BlameHistoryPermalink
  • Nigel McNie's avatar
    Security fix: Prevent institution admins from administering site admins. · 05ee1ac7
    Nigel McNie authored Oct 23, 2009
    
    
    Without this fix, institution admins can login as site admins and do
    other such administrative tasks (e.g. reset their password), if the site
    admin joins their institution.
    
    Reported by Ruslan Kabalin <r.kabalin@lancaster.ac.uk>, who supplied a
    patch. My patch skips adding an extra method to find out if a given user
    is an admin, though it's not any more performant.
    
    Signed-off-by: default avatarNigel McNie <nigel@catalyst.net.nz>
    05ee1ac7