The permissions are not correct.
When you give users the "create drag & drop galleries" permission they can create the gallerie's but they can also edit other users their gallerie's.
So the permission "edit any & drop galleries" and "edit own & drop galleries" don't work.
The problem is on line 353.
They only do this check:
if(user_access('create drag & drop galleries')) {

And it needs to be like this:
global $user;
if(user_access('create drag & drop galleries') && $user->uid == $node->uid || user_access('edit any & drop galleries')) {

Please fix this !
Ty

Comments

nicasso’s picture

Issue summary: View changes
Priority: Major » Minor
Status: Active » Closed (won't fix)