From 1fa9f86af76141dee786b45083ebcdb72f49981a Mon Sep 17 00:00:00 2001 From: arno Date: Sun, 16 Aug 2009 23:02:38 +0200 Subject: [PATCH] fixes: admin cannot modify other users items --- api.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/api.php b/api.php index fda62ff..9b268dc 100644 --- a/api.php +++ b/api.php @@ -239,7 +239,7 @@ function main ($con) { if (!isset ($feature)) { error_unreferenced ($id); } - if ($feature->user != $user) { + if (($feature->user != $user) && ($user != "admin")) { error_unauthorized (); } -- 2.39.2