summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorClaus-Justus Heine <himself@claus-justus-heine.de>2022-01-30 22:27:56 +0100
committerMichaIng (Rebase PR Action) <micha@dietpi.com>2022-02-23 00:17:36 +0000
commit641ea6d7cb6acb0c550977c511b6576ef1f6e795 (patch)
treea6cc57cf61b5bf7347d57e538bed70a43ce011d5
parentedfa6033b99338d4f18cfdfaa3d1e2b14691d638 (diff)
downloadnextcloud-server-641ea6d7cb6acb0c550977c511b6576ef1f6e795.tar.gz
nextcloud-server-641ea6d7cb6acb0c550977c511b6576ef1f6e795.zip
Allow sub-admins to access delegated settings.
Signed-off-by: Claus-Justus Heine <himself@claus-justus-heine.de>
-rw-r--r--lib/private/Settings/Manager.php25
1 files changed, 11 insertions, 14 deletions
diff --git a/lib/private/Settings/Manager.php b/lib/private/Settings/Manager.php
index ebda3fe021d..84fbf9426b0 100644
--- a/lib/private/Settings/Manager.php
+++ b/lib/private/Settings/Manager.php
@@ -335,23 +335,20 @@ class Manager implements IManager {
public function getAllowedAdminSettings(string $section, IUser $user): array {
$isAdmin = $this->groupManager->isAdmin($user->getUID());
- $isSubAdmin = $this->subAdmin->isSubAdmin($user);
- $subAdminOnly = !$isAdmin && $isSubAdmin;
-
- if ($subAdminOnly) {
- // not an admin => look if the user is still authorized to access some
- // settings
- $subAdminSettingsFilter = function (ISettings $settings) {
- return $settings instanceof ISubAdminSettings;
- };
- $appSettings = $this->getSettings('admin', $section, $subAdminSettingsFilter);
- } elseif ($isAdmin) {
+ if ($isAdmin) {
$appSettings = $this->getSettings('admin', $section);
} else {
$authorizedSettingsClasses = $this->mapper->findAllClassesForUser($user);
- $authorizedGroupFilter = function (ISettings $settings) use ($authorizedSettingsClasses) {
- return in_array(get_class($settings), $authorizedSettingsClasses) === true;
- };
+ if ($this->subAdmin->isSubAdmin($user)) {
+ $authorizedGroupFilter = function (ISettings $settings) use ($authorizedSettingsClasses) {
+ return $settings instanceof ISubAdminSettings
+ || in_array(get_class($settings), $authorizedSettingsClasses) === true;
+ };
+ } else {
+ $authorizedGroupFilter = function (ISettings $settings) use ($authorizedSettingsClasses) {
+ return in_array(get_class($settings), $authorizedSettingsClasses) === true;
+ };
+ }
$appSettings = $this->getSettings('admin', $section, $authorizedGroupFilter);
}