Skip to content

Commit 88d8708

Browse files
authored
FIX / Admin locks himself out of a container's configuration (#1255)
* use config right to access container config form * update CHANGELOG.md * import missing class
1 parent 06bd041 commit 88d8708

2 files changed

Lines changed: 9 additions & 6 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,12 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](http://keepachangelog.com/)
66
and this project adheres to [Semantic Versioning](http://semver.org/).
77

8+
## [Unreleased]
9+
10+
### Fixed
11+
12+
- Fix administrators losing access to a block's configuration after setting a profile to "no access" on that block.
13+
814
## [1.24.5] - 2026-09-11
915

1016
### Fixed

‎front/container.form.php‎

Lines changed: 3 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -73,12 +73,9 @@
7373
Html::back();
7474
} else {
7575

76-
if ((int) $_GET['id'] > 0) {
77-
$right = PluginFieldsProfile::getRightOnContainer($_SESSION['glpiactiveprofile']['id'], $_GET['id']);
78-
if ($right < READ) {
79-
throw new AccessDeniedHttpException();
80-
}
81-
}
76+
// Admin config screen: gate with the standard "config" right, not the per-profile
77+
// block-visibility right (which would let an admin lock himself out of the config).
78+
$container->check((int) $_GET['id'] > 0 ? (int) $_GET['id'] : -1, READ);
8279

8380
Html::header(
8481
__('Additional fields', 'fields'),

0 commit comments

Comments
 (0)