Skip to content

Commit 74b28de

Browse files
authored
fix security leaphole
1 parent 133a531 commit 74b28de

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

src/UserLoginAsController.php

+3
Original file line numberDiff line numberDiff line change
@@ -16,6 +16,9 @@ public function loginAs($user)
1616
} else {
1717
$user = \App\Models\User::findOrFail($user);
1818
}
19+
if( method_exists($user,'isManager') && $user->isManager()) {
20+
abort(403, "Het is niet mogelijk om in te loggen alsof je een andere admin bent");
21+
}
1922
Auth::login($user);
2023

2124
Session::put('loginas', $current_user_id);

0 commit comments

Comments
 (0)