Browse Source

Merge pull request #1936 from pulzarraider/patch-3

Added missing security check in inline show action
Thomas 11 years ago
parent
commit
7e7245288e
1 changed files with 1 additions and 1 deletions
  1. 1 1
      Resources/views/CRUD/list__action_show.html.twig

+ 1 - 1
Resources/views/CRUD/list__action_show.html.twig

@@ -9,7 +9,7 @@ file that was distributed with this source code.
 
 
 #}
 #}
 
 
-{% if admin.hasRoute('show') %}
+{% if admin.isGranted('VIEW', object) and admin.hasRoute('show') %}
     <a href="{{ admin.generateObjectUrl('show', object) }}" class="btn view_link btn-small" title="{{ 'action_show'|trans({}, 'SonataAdminBundle') }}">
     <a href="{{ admin.generateObjectUrl('show', object) }}" class="btn view_link btn-small" title="{{ 'action_show'|trans({}, 'SonataAdminBundle') }}">
         <i class="icon-zoom-in"></i>
         <i class="icon-zoom-in"></i>
         {{ 'action_show'|trans({}, 'SonataAdminBundle') }}
         {{ 'action_show'|trans({}, 'SonataAdminBundle') }}