From bc5e661ea1a932595b5cf242e86ce367c0035540 Mon Sep 17 00:00:00 2001 From: FreddleSpl0it Date: Tue, 14 Mar 2023 18:41:05 +0100 Subject: [PATCH] [Web] create ratelimit acl on iam mbox creation --- data/web/inc/functions.ratelimit.inc.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/web/inc/functions.ratelimit.inc.php b/data/web/inc/functions.ratelimit.inc.php index f9e7a71a..f311533f 100644 --- a/data/web/inc/functions.ratelimit.inc.php +++ b/data/web/inc/functions.ratelimit.inc.php @@ -92,7 +92,7 @@ function ratelimit($_action, $_scope, $_data = null) { ); continue; } - if (!hasMailboxObjectAccess($_SESSION['mailcow_cc_username'], $_SESSION['mailcow_cc_role'], $object) + if (!hasMailboxObjectAccess($_SESSION['mailcow_cc_username'], $_SESSION['mailcow_cc_role'], $object) && !$_SESSION['iam_create_login'] || ($_SESSION['mailcow_cc_role'] != 'admin' && $_SESSION['mailcow_cc_role'] != 'domainadmin')) { $_SESSION['return'][] = array( 'type' => 'danger',