ensure that if the dasboardID is negative, it will not bypass the checking of the right (#12398)

pull/12412/head
Augustin 8 years ago committed by Torkel Ödegaard
parent 5a2cf5863d
commit ef0bf9f701
  1. 6
      pkg/api/annotations.go

@ -272,9 +272,9 @@ func canSaveByDashboardID(c *m.ReqContext, dashboardID int64) (bool, error) {
return false, nil
}
if dashboardID > 0 {
guardian := guardian.New(dashboardID, c.OrgId, c.SignedInUser)
if canEdit, err := guardian.CanEdit(); err != nil || !canEdit {
if dashboardID != 0 {
guard := guardian.New(dashboardID, c.OrgId, c.SignedInUser)
if canEdit, err := guard.CanEdit(); err != nil || !canEdit {
return false, err
}
}

Loading…
Cancel
Save