aboutsummaryrefslogtreecommitdiff
path: root/app/class/controlleruser.php
diff options
context:
space:
mode:
authorvincent-peugnet <v.peugnet@free.fr>2018-12-24 12:04:27 +0100
committervincent-peugnet <v.peugnet@free.fr>2018-12-24 12:04:27 +0100
commit055bbcbd61a56e39408e7d2b9d83c47fc76daa20 (patch)
tree3d3ced3c3147346e382a9ca53a499fd35f21749a /app/class/controlleruser.php
parent8d8f625ea20e10cf6fb053fab73c2ef7a559dc87 (diff)
downloadwcms-055bbcbd61a56e39408e7d2b9d83c47fc76daa20.tar.gz
wcms-055bbcbd61a56e39408e7d2b9d83c47fc76daa20.zip
user admin protection
Diffstat (limited to 'app/class/controlleruser.php')
-rw-r--r--app/class/controlleruser.php11
1 files changed, 10 insertions, 1 deletions
diff --git a/app/class/controlleruser.php b/app/class/controlleruser.php
index 00b7246..9daf1fb 100644
--- a/app/class/controlleruser.php
+++ b/app/class/controlleruser.php
@@ -36,7 +36,16 @@ class Controlleruser extends Controller
{
if($_POST['action'] === 'delete') {
$user = new User($_POST);
- $this->showtemplate('userconfirmdelete', ['userdelete' => $user]);
+ $user = $this->usermanager->get($user);
+ if($user !== false) {
+ if($user->isadmin() && $this->usermanager->admincount() === 1) {
+ $this->showtemplate('userconfirmdelete', ['userdelete' => $user, 'candelete' => false]);
+ } else {
+ $this->showtemplate('userconfirmdelete', ['userdelete' => $user, 'candelete' => true]);
+ }
+ } else {
+ $this->routedirect('user');
+ }
} elseif ($_POST['action'] == 'confirmdelete') {
$user = new User($_POST);
$this->usermanager->delete($user);