users: don't allow gifting upgrades to demote privileged users.
Don't allow gifting Gold or Platinum upgrades to users above Platinum level. Fixes an exploit where you could demote Builders and above by gifting them an upgrade.
This commit is contained in:
@@ -54,6 +54,8 @@ class UserPromotion
|
||||
raise User::PrivilegeError, "You can't promote other users to your rank or above"
|
||||
elsif user.level >= promoter.level
|
||||
raise User::PrivilegeError, "You can't promote or demote other users at your rank or above"
|
||||
elsif is_upgrade && user.is_builder?
|
||||
raise User::PrivilegeError, "You can't upgrade a user that is above Platinum level"
|
||||
end
|
||||
end
|
||||
|
||||
|
||||
Reference in New Issue
Block a user