Security correction
This commit is contained in:
parent
eaff14acc6
commit
0bcab27a1d
|
|
@ -166,7 +166,7 @@ class OrganizationController extends AbstractController
|
||||||
}
|
}
|
||||||
$uos = $this->entityManager
|
$uos = $this->entityManager
|
||||||
->getRepository(UsersOrganizations::class)
|
->getRepository(UsersOrganizations::class)
|
||||||
->findBy(['organization' => $organization, 'isActive' => true]);
|
->findBy(['organization' => $organization]);
|
||||||
|
|
||||||
$users = $this->userService->formatOrgUsers($uos);
|
$users = $this->userService->formatOrgUsers($uos);
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -11,12 +11,14 @@
|
||||||
<div>
|
<div>
|
||||||
{% if is_granted("ROLE_SUPER_ADMIN") %}
|
{% if is_granted("ROLE_SUPER_ADMIN") %}
|
||||||
<a href="{{ path('user_delete', {'id': user.id}) }}" class="btn btn-danger">Supprimer</a>
|
<a href="{{ path('user_delete', {'id': user.id}) }}" class="btn btn-danger">Supprimer</a>
|
||||||
{% endif %}
|
|
||||||
{% if user.active %}
|
{% if user.active %}
|
||||||
<a href="{{ path('user_deactivate', {'id': user.id}) }}" class="btn btn-danger">Désactiver</a>
|
<a href="{{ path('user_deactivate', {'id': user.id}) }}"
|
||||||
|
class="btn btn-danger">Désactiver</a>
|
||||||
{% else %}
|
{% else %}
|
||||||
<a href="{{ path('user_activate', {'id': user.id}) }}" class="btn btn-success">Activer</a>
|
<a href="{{ path('user_activate', {'id': user.id}) }}" class="btn btn-success">Activer</a>
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
{% endif %}
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
</div>
|
</div>
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue