#400 add defanged_admin config to allow disabling of risky actions

This commit is contained in:
Oliver Gorwits
2018-04-22 18:49:15 +01:00
parent f1d546deea
commit 75a199690c
3 changed files with 5 additions and 4 deletions

View File

@@ -31,7 +31,7 @@ sub _make_password {
}
}
ajax '/ajax/control/admin/users/add' => require_role admin => sub {
ajax '/ajax/control/admin/users/add' => require_role setting('defanged_admin') => sub {
send_error('Bad Request', 400) unless _sanity_ok();
schema('netdisco')->txn_do(sub {
@@ -48,7 +48,7 @@ ajax '/ajax/control/admin/users/add' => require_role admin => sub {
});
};
ajax '/ajax/control/admin/users/del' => require_role admin => sub {
ajax '/ajax/control/admin/users/del' => require_role setting('defanged_admin') => sub {
send_error('Bad Request', 400) unless _sanity_ok();
schema('netdisco')->txn_do(sub {
@@ -57,7 +57,7 @@ ajax '/ajax/control/admin/users/del' => require_role admin => sub {
});
};
ajax '/ajax/control/admin/users/update' => require_role admin => sub {
ajax '/ajax/control/admin/users/update' => require_role setting('defanged_admin') => sub {
send_error('Bad Request', 400) unless _sanity_ok();
schema('netdisco')->txn_do(sub {