From d08f851c0bac2b3597891c2d906ecbfa82db02cc Mon Sep 17 00:00:00 2001 From: Franz Liedke Date: Wed, 21 Aug 2019 23:48:24 +0200 Subject: [PATCH] When signups are prohibited, respond with HTTP 403 --- src/User/Command/RegisterUserHandler.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/User/Command/RegisterUserHandler.php b/src/User/Command/RegisterUserHandler.php index 2ece57920..6925a86fa 100644 --- a/src/User/Command/RegisterUserHandler.php +++ b/src/User/Command/RegisterUserHandler.php @@ -72,7 +72,7 @@ class RegisterUserHandler $data = $command->data; if (! $this->settings->get('allow_sign_up')) { - $this->assertAdmin($actor); + $this->assertPermission($actor->can('administrate')); } $password = Arr::get($data, 'attributes.password');