From 8af976733e7d0d814c06804c48e4cd38cbe6e8dd Mon Sep 17 00:00:00 2001 From: Chris Sharp Date: Tue, 21 Apr 2015 17:10:49 -0400 Subject: [PATCH] LP#1446860 Staff were able to edit their own accounts. This change reverses what appears to be a thinko in the original programming. If the editing user is the same as the user being edited, disable the Save button. Signed-off-by: Chris Sharp Signed-off-by: Ben Shum --- Open-ILS/web/js/ui/default/actor/user/register.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Open-ILS/web/js/ui/default/actor/user/register.js b/Open-ILS/web/js/ui/default/actor/user/register.js index ced646fbae..e5846fc948 100644 --- a/Open-ILS/web/js/ui/default/actor/user/register.js +++ b/Open-ILS/web/js/ui/default/actor/user/register.js @@ -302,7 +302,7 @@ function load() { dojo.connect(setExpireDate, 'onClick', setExpireDateHandler); - if(!patron.isnew() && !checkGrpAppPerm(patron.profile()) && patron.id() != openils.User.user.id()) { + if(!patron.isnew() && !checkGrpAppPerm(patron.profile()) && patron.id() == openils.User.user.id()) { // we are not allowed to edit this user, so disable the save option saveButton.attr('disabled', true); saveCloneButton.attr('disabled', true); -- 2.43.2