Make WordPress Core

Changeset 149


Ignore:
Timestamp:
06/03/2003 12:08:51 AM (23 years ago)
Author:
mikelittle
Message:

Fixed admin level security problem.
Plus an user -> a user

Location:
trunk/wp-admin
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/wp-admin/b2edit.php

    r143 r149  
    128128            $postdata = get_postdata($post);
    129129            $authordata = get_userdata($postdata["Author_ID"]);
    130             if ($user_level < $authordata[13])
     130            if ($user_level < $authordata->user_level)
    131131                die ('You don&#8217;t have the right to edit <strong>'.$authordata[1].'</strong>&#8217;s posts.');
    132132
     
    219219        $authordata = get_userdata($postdata["Author_ID"]);
    220220
    221         if ($user_level < $authordata[13])
     221        if ($user_level < $authordata->user_level)
    222222            die ("You don't have the right to delete <b>".$authordata[1]."</b>'s posts.");
    223223
  • trunk/wp-admin/b2edit.showposts.php

    r143 r149  
    236236                <strong><?php the_time('Y/m/d @ H:i:s'); ?></strong> [ <a href="b2edit.php?p=<?php echo $id ?>&c=1"><?php comments_number('no comments', '1 comment', "% comments") ?></a>
    237237                <?php
    238                 if (($user_level > $authordata[13]) or ($user_login == $authordata[1])) {
     238                if (($user_level > $authordata->user_level) or ($user_login == $authordata->user_login)) {
    239239                echo " - <a href='b2edit.php?action=edit&amp;post=$id";
    240240                if ($m)
     
    275275                    <?php comment_date('Y/m/d') ?> @ <?php comment_time() ?>
    276276                    <?php
    277                     if (($user_level > $authordata[13]) or ($user_login == $authordata[1])) {
     277                    if (($user_level > $authordata->user_level) or ($user_login == $authordata->user_login)) {
    278278                        echo "[ <a href=\"b2edit.php?action=editcomment&amp;comment=".$commentdata->comment_ID."\">Edit</a>";
    279279                        echo " - <a href=\"b2edit.php?action=deletecomment&amp;p=".$post->ID."&amp;comment=".$commentdata->comment_ID."\">Delete</a> ]";
  • trunk/wp-admin/b2team.php

    r127 r149  
    3434
    3535    $user_data = get_userdata($id);
    36     $usertopromote_level = $user_data[13];
     36    $usertopromote_level = $user_data->user_level;
    3737
    3838    if ($user_level <= $usertopromote_level) {
    39         die('Can&#8217;t change the level of an user whose level is higher than yours.');
     39        die('Can&#8217;t change the level of a user whose level is higher than yours.');
    4040    }
    4141
     
    6666
    6767    if ($user_level <= $usertodelete_level)
    68         die('Can&#8217;t delete an user whose level is higher than yours.');
     68        die('Can&#8217;t delete a user whose level is higher than yours.');
    6969
    7070    $sql = "DELETE FROM $tableusers WHERE ID = $id";
     
    8484    ?>
    8585
    86 <div class="wrap"><p>Click on an user&#8217;s login name to see his complete profile.<br />
     86<div class="wrap"><p>Click on a user&#8217;s login name to see his complete profile.<br />
    8787    To edit your profile, click on your login name.</p>
    8888</div>
     
    192192    if ($user_level >= 3) { ?>
    193193<div class="wrap">
    194   <p>To delete an user, bring his level to zero, then click on the red X.<br />
    195     <strong>Warning:</strong> deleting an user also deletes all posts made by this user.
     194  <p>To delete a user, bring his level to zero, then click on the red X.<br />
     195    <strong>Warning:</strong> deleting a user also deletes all posts made by this user.
    196196  </p>
    197197</div>
Note: See TracChangeset for help on using the changeset viewer.