Always allow users to see their own account. fixes #1626

This commit is contained in:
Toby Zerner 2018-11-11 14:25:21 +10:30
parent ebcc173496
commit b68f183e86

View File

@ -39,7 +39,11 @@ class UserPolicy extends AbstractPolicy
public function find(User $actor, Builder $query)
{
if ($actor->cannot('viewUserList')) {
$query->whereRaw('FALSE');
if ($actor->isGuest()) {
$query->whereRaw('FALSE');
} else {
$query->where('id', $actor->id);
}
}
}
}