Download & Extend

pontomail admin block link access control broken

Project:Pontomail Webmail Client
Version:4.7.x-1.x-dev
Component:Code
Category:bug report
Priority:normal
Assigned:Unassigned
Status:active

Issue Summary

The admin block link for pontomail is displayed to anonymous users, even though they are configured to have NO access rights on my site. Worse, clicking on the link actually displays the admin settings for pontomail to those same anonymous users who shouldn't have any rights, much less admin rights!

Attached is a screen shot (GIF) showing an anonymous, no rights user view of the admin page.

AttachmentSize
pontoadmin.gif12.91 KB
nobody click here