mirror of
https://github.com/discourse/discourse.git
synced 2025-02-17 07:52:45 +08:00
SECURITY: Don't allow moderators to view the admins inbox
This commit is contained in:
parent
0b8e7d88fe
commit
18d35bf64a
|
@ -540,7 +540,8 @@ class TopicQuery
|
|||
SELECT group_id
|
||||
FROM group_users
|
||||
WHERE user_id = #{user.id.to_i}
|
||||
OR #{user.staff?}
|
||||
OR #{user.admin?}
|
||||
OR (#{user.staff?} AND group_id <> #{Group::AUTO_GROUPS[:admins]})
|
||||
)
|
||||
)
|
||||
AND group_id IN (SELECT id FROM groups WHERE name ilike ?)
|
||||
|
|
Loading…
Reference in New Issue
Block a user