ensure that if the dasboardID is negative, it will not bypass the checking of the right (#12398)

pull/12412/head
Augustin 8 years ago committed by Torkel Ödegaard
parent 5a2cf5863d
commit ef0bf9f701
  1. 6
      pkg/api/annotations.go

@ -272,9 +272,9 @@ func canSaveByDashboardID(c *m.ReqContext, dashboardID int64) (bool, error) {
return false, nil return false, nil
} }
if dashboardID > 0 { if dashboardID != 0 {
guardian := guardian.New(dashboardID, c.OrgId, c.SignedInUser) guard := guardian.New(dashboardID, c.OrgId, c.SignedInUser)
if canEdit, err := guardian.CanEdit(); err != nil || !canEdit { if canEdit, err := guard.CanEdit(); err != nil || !canEdit {
return false, err return false, err
} }
} }

Loading…
Cancel
Save