Administrator groups can be limited to a list of advanced permissions
(add_user, settings, database, …). None of it was applied:
- PageAuthorization::checkPermissions() and checkResellerPermissions(),
called without a page (every controller's requirePermission()), took the
page from SCRIPT_FILENAME. Under the front controller that is always
Public/index.php, so the page checked was "index", which no rule names:
every page opened for every administrator and reseller.
- post.php saves all 63 admin forms and checked the page "post", also
unnamed. A restricted administrator could save anything — settings,
servers, or their own user with member_group_id=1, becoming a full admin.
The page now comes from AdminHelpers::getPageName() (the route's
PAGE_NAME). post.php holds each action to the rule of the page it saves,
through checkPostAction(): add vs edit is decided by the form's `edit`
field instead of ?id=, mass_delete_* map to mass_delete, TMDb category
import to categories. The Enigma2 device page had no rule at all and now
has the MAG one (add_e2 / edit_e2). The administrator's own profile and
module settings stay open, as before.
Full administrators (group 1, or a group with no advanced list) are
unaffected.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01V2uBUbGApb4A7Rbcoi7dxA