Commit 2d8259c7 authored by Gábor Hojtsy's avatar Gábor Hojtsy

#25605 by Rob Loach et al: disallow editing user data of uid 0

parent 40d406f7
......@@ -841,7 +841,7 @@ function user_view_access($account) {
}
function user_edit_access($account) {
return ($GLOBALS['user']->uid == $account->uid) || user_access('administer users');
return (($GLOBALS['user']->uid == $account->uid) || user_access('administer users')) && $account->uid > 0;
}
function user_load_self($arg) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment