Skip to content

Commit c5c9b33

Browse files
committed
Session: limit access to admin session list to authorized user (admin, session admin and teachers) -refs BT#21330
1 parent 63d9dec commit c5c9b33

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

main/inc/lib/sessionmanager.lib.php

+4
Original file line numberDiff line numberDiff line change
@@ -491,6 +491,10 @@ public static function getSessionsForAdmin(
491491

492492
$userId = (int) $userId;
493493

494+
if (!api_is_platform_admin() && !api_is_session_admin() && !api_is_teacher()) {
495+
api_not_allowed(true);
496+
}
497+
494498
if (!api_is_platform_admin()) {
495499
if (api_is_session_admin() &&
496500
'false' === api_get_setting('allow_session_admins_to_manage_all_sessions')

0 commit comments

Comments
 (0)