Security correction

This commit is contained in:
Charles 2025-09-03 16:00:42 +02:00
parent eaff14acc6
commit 0bcab27a1d
2 changed files with 8 additions and 6 deletions

View File

@ -166,7 +166,7 @@ class OrganizationController extends AbstractController
}
$uos = $this->entityManager
->getRepository(UsersOrganizations::class)
->findBy(['organization' => $organization, 'isActive' => true]);
->findBy(['organization' => $organization]);
$users = $this->userService->formatOrgUsers($uos);

View File

@ -11,11 +11,13 @@
<div>
{% if is_granted("ROLE_SUPER_ADMIN") %}
<a href="{{ path('user_delete', {'id': user.id}) }}" class="btn btn-danger">Supprimer</a>
{% endif %}
{% if user.active %}
<a href="{{ path('user_deactivate', {'id': user.id}) }}" class="btn btn-danger">Désactiver</a>
{% else %}
<a href="{{ path('user_activate', {'id': user.id}) }}" class="btn btn-success">Activer</a>
{% if user.active %}
<a href="{{ path('user_deactivate', {'id': user.id}) }}"
class="btn btn-danger">Désactiver</a>
{% else %}
<a href="{{ path('user_activate', {'id': user.id}) }}" class="btn btn-success">Activer</a>
{% endif %}
{% endif %}
</div>