Skip to content

Conversation

xLive
Copy link
Member

@xLive xLive commented Aug 21, 2025

This PR changes the defaultPermission argument in hasObjectPermissionTo in the admin & admin2 resources from true to false.

This now denies any ACL right that is not explicitly set instead of allowing it, preventing cases where an admin action is missing in conf/ACL.xml or when the admin resource fails to create its ACL rights.

@xLive xLive requested a review from jlillis as a code owner August 21, 2025 16:22
@Dutchman101 Dutchman101 merged commit 0495b38 into multitheftauto:master Aug 21, 2025
1 check passed
@xLive xLive deleted the fix/admin-acl-default-deny branch August 22, 2025 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants