From b4a09384c388c7e906251c3a750fceb9960b5b56 Mon Sep 17 00:00:00 2001 From: Johannes Helmold Date: Tue, 22 Sep 2026 12:51:38 +0200 Subject: [PATCH 1/2] Fix: Set user to not editable if the user is the current user. Set the user of the users table in GSA to not editable, when the user of the resource is the current user. --- src/gmp_get.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/src/gmp_get.c b/src/gmp_get.c index d08d95d49..333043099 100644 --- a/src/gmp_get.c +++ b/src/gmp_get.c @@ -349,9 +349,13 @@ send_get_common (const char *type, get_data_t *get, iterator_t *iterator, && (strcmp (get_iterator_owner_name (iterator), current_credentials.username) == 0)) - /* Or the user is effectively the owner. */ - || acl_user_has_super (current_credentials.uuid, - get_iterator_owner (iterator)) + /* Or the user is effectively the owner and the user is not the user + * of the resource if the resource is of type user. */ + || (acl_user_has_super (current_credentials.uuid, + get_iterator_owner (iterator)) + && (strcmp (type, "user") + || strcmp (get_iterator_name (iterator), current_credentials.username) + || acl_user_is_super_admin (current_credentials.uuid))) /* Or the user has Admin rights and the resource is a permission or a * report format... */ || (current_credentials.uuid From adb49981bebc3331536cdfe67560c8b20ba54b5b Mon Sep 17 00:00:00 2001 From: Johannes Helmold Date: Wed, 23 Sep 2026 14:39:41 +0200 Subject: [PATCH 2/2] Use uuid instead of username for user identification. --- src/gmp_get.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/gmp_get.c b/src/gmp_get.c index 333043099..47f330ae6 100644 --- a/src/gmp_get.c +++ b/src/gmp_get.c @@ -354,7 +354,7 @@ send_get_common (const char *type, get_data_t *get, iterator_t *iterator, || (acl_user_has_super (current_credentials.uuid, get_iterator_owner (iterator)) && (strcmp (type, "user") - || strcmp (get_iterator_name (iterator), current_credentials.username) + || strcmp (get_iterator_uuid (iterator), current_credentials.uuid) || acl_user_is_super_admin (current_credentials.uuid))) /* Or the user has Admin rights and the resource is a permission or a * report format... */