1
0
mirror of https://github.com/flarum/core.git synced 2025-07-30 21:20:24 +02:00

Don't allow guests into the admin area

This commit is contained in:
Toby Zerner
2015-03-30 12:43:55 +10:30
parent 4b71c32e8b
commit 8604ed99ec

View File

@@ -16,12 +16,11 @@ class LoginWithCookieAndCheckAdmin
public function handle($request, Closure $next)
{
if (($token = $request->cookie('flarum_remember')) &&
($accessToken = AccessToken::where('id', $token)->first())) {
$user = $accessToken->user;
if (! $user->isAdmin()) {
die('ur not an admin');
}
$this->actor->setUser($user);
($accessToken = AccessToken::where('id', $token)->first()) &&
$accessToken->user->isAdmin()) {
$this->actor->setUser($accessToken->user);
} else {
die('ur not an admin');
}
return $next($request);