Bug #372

Admins with List Servers can access Server RCON page.

Added by Max Krivanek 102 days ago. Updated 100 days ago.

Status:Resolved Start:09/26/2008
Priority:High Due date:
Assigned to:Jannik Hartung % Done:

100%

Category:Web Panel
Target version:1.3.1

Description

Admins with just the ability to list can access the Server's RCON page by manually typing in the URL.

Ex. http://example.com/sourcebans/index.php?p=admin&c=servers&o=rcon&id=1

They can NOT send any RCON commands due to a check in SB-callback.php.

Associated revisions

Revision 165
Added by Jannik Hartung 100 days ago

  • Improved use of the archives!!
  • Fixed #371 - Admins can change their own/others groups!
  • Fixed #372 - Admins with List Servers can access Server RCON page, but can't send rcon commands
  • Fixed #373 - Admins with List Mods can edit mods
  • Fixed some ugly errormessages
  • Added #246 - Custom ban reasons in dropdown menu
  • Fixed #354 - unify comment-add-link on submission and protest pages
  • Enabled Kickit by default
  • If player was found with Kickit server is shown in ban details

History

Updated by Max Krivanek 102 days ago

They also can access other pages, such as Edit Servers, etc.

Updated by Jannik Hartung 100 days ago

  • Status changed from New to Resolved
  • Assigned to set to Jannik Hartung
  • Target version set to 1.3.1
  • % Done changed from 0 to 100

no, they can't access edit servers page!
just rcon, but that was not that urgent ;)

Also available in: Atom PDF