Selaa lähdekoodia

Added missing security check in inline show action

Andrej Hudec 11 vuotta sitten
vanhempi
commit
f1ed1aaf5a
1 muutettua tiedostoa jossa 1 lisäystä ja 1 poistoa
  1. 1 1
      Resources/views/CRUD/list__action_show.html.twig

+ 1 - 1
Resources/views/CRUD/list__action_show.html.twig

@@ -9,7 +9,7 @@ file that was distributed with this source code.
 
 #}
 
-{% if admin.hasRoute('show') %}
+{% if admin.isGranted('VIEW', object) and admin.hasRoute('show') %}
     <a href="{{ admin.generateObjectUrl('show', object) }}" class="btn view_link btn-small" title="{{ 'action_show'|trans({}, 'SonataAdminBundle') }}">
         <i class="icon-zoom-in"></i>
         {{ 'action_show'|trans({}, 'SonataAdminBundle') }}