Patch #9317 ยป 0001-Admin-user-is-always-authorized-when-no-context-is-g.patch
app/models/user.rb | ||
---|---|---|
432 | 432 |
(block_given? ? yield(role, self) : true) |
433 | 433 |
} |
434 | 434 |
else |
435 |
false |
|
435 |
# Admin users are always authorized when no context is given |
|
436 |
return true if admin? |
|
436 | 437 |
end |
437 | 438 |
end |
438 | 439 |