Security correction

This commit is contained in:
Charles 2025-09-03 16:00:42 +02:00
parent eaff14acc6
commit 0bcab27a1d
2 changed files with 8 additions and 6 deletions

View File

@ -166,7 +166,7 @@ class OrganizationController extends AbstractController
} }
$uos = $this->entityManager $uos = $this->entityManager
->getRepository(UsersOrganizations::class) ->getRepository(UsersOrganizations::class)
->findBy(['organization' => $organization, 'isActive' => true]); ->findBy(['organization' => $organization]);
$users = $this->userService->formatOrgUsers($uos); $users = $this->userService->formatOrgUsers($uos);

View File

@ -11,12 +11,14 @@
<div> <div>
{% if is_granted("ROLE_SUPER_ADMIN") %} {% if is_granted("ROLE_SUPER_ADMIN") %}
<a href="{{ path('user_delete', {'id': user.id}) }}" class="btn btn-danger">Supprimer</a> <a href="{{ path('user_delete', {'id': user.id}) }}" class="btn btn-danger">Supprimer</a>
{% endif %}
{% if user.active %} {% if user.active %}
<a href="{{ path('user_deactivate', {'id': user.id}) }}" class="btn btn-danger">Désactiver</a> <a href="{{ path('user_deactivate', {'id': user.id}) }}"
class="btn btn-danger">Désactiver</a>
{% else %} {% else %}
<a href="{{ path('user_activate', {'id': user.id}) }}" class="btn btn-success">Activer</a> <a href="{{ path('user_activate', {'id': user.id}) }}" class="btn btn-success">Activer</a>
{% endif %} {% endif %}
{% endif %}
</div> </div>
</div> </div>