FIX: check trust level of user creating invite for group (#12993)

This commit is contained in:
Hariraj Venkatesan
2021-05-10 22:17:32 +05:30
committed by GitHub
parent 02f0acc41b
commit c473cde997
2 changed files with 12 additions and 0 deletions

View File

@@ -322,6 +322,8 @@ class GroupsController < ApplicationController
unless current_user.staff?
RateLimiter.new(current_user, "public_group_membership", 3, 1.minute).performed!
end
elsif !current_user.has_trust_level?(SiteSetting.min_trust_level_to_allow_invite.to_i)
raise Discourse::InvalidAccess
end
emails = []