Even anonymous users can edit the user_term settings. Attached a patch.

CommentFileSizeAuthor
access.patch899 bytesnaxoc

Comments

naxoc’s picture

Status: Active » Needs review

Aaaand... Setting status.

joachim’s picture

Priority: Normal » Critical

EEeeeeech!

Good catch! Will commit as soon as I'm near my own system!

joachim’s picture

Status: Needs review » Fixed

Thanks for the bug report and the patch.

Committed the patch (with indentation tweaks).

#747222 by naxoc: Fixed no access check to admin page.

I'm going to make a new beta release with this fix in it.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.