From 339053e73e0343131d148efa5b895ede505fffcc Mon Sep 17 00:00:00 2001 From: Guy Sartorelli Date: Fri, 17 Apr 2020 10:14:59 +1200 Subject: [PATCH] Fix canEdit permissions. If permissions earlier in the inheritance chain fail, we should not allow users to edit posts. If permissions earlier in the inheritance chain succeed, we should still go through the checks in this method. --- src/Model/BlogPost.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/Model/BlogPost.php b/src/Model/BlogPost.php index 77f36e43d..4b2e1938f 100644 --- a/src/Model/BlogPost.php +++ b/src/Model/BlogPost.php @@ -564,8 +564,8 @@ public function canEdit($member = null) { $member = $this->getMember($member); - if (parent::canEdit($member)) { - return true; + if (!parent::canEdit($member)) { + return false; } $parent = $this->Parent();