Quote:
Originally Posted by smdani
- I have just see at your articles site that someone hacked your articles system, maybe there is a way of editing articles without permissions
|
In article.php, Search For:
Code:
$article = $DB_site->query_first("
SELECT article.*, articlepost.postbody AS content, article.articlehash FROM " . TABLE_PREFIX . "article AS article
INNER JOIN " . TABLE_PREFIX . "articlepost AS articlepost ON(articlepost.postid = article.firstpostid)
WHERE article.articleid=$articleid");
Just
after it, add this:
Code:
if ($article['articleuserid'] !== $bbuserinfo['userid'])
{
if (!($permissions['articlepermissions'] & CANEDOTHART))
{
print_no_permission();
}
}
else
{
if (!($permissions['articlepermissions'] & CANEDOWNART))
{
print_no_permission();
}
}
That should fix it