[FIX] auth of pagenew
authorXavier Morel <xmo@openerp.com>
Thu, 24 Oct 2013 11:17:10 +0000 (13:17 +0200)
committerXavier Morel <xmo@openerp.com>
Thu, 24 Oct 2013 11:17:10 +0000 (13:17 +0200)
bzr revid: xmo@openerp.com-20131024111710-5ghadng4we3p2cgg

addons/website/controllers/main.py

index 30f384a..60d20f5 100644 (file)
@@ -51,8 +51,7 @@ class Website(openerp.addons.web.controllers.main.Home):
     def index(self, **kw):
         return self.page("website.homepage")
 
-    # FIXME: auth, if /pagenew known anybody can create new empty page
-    @website.route('/pagenew/<path:path>', type='http', auth="admin")
+    @website.route('/pagenew/<path:path>', type='http', auth="user")
     def pagenew(self, path, noredirect=NOPE):
         module = 'website'
         # completely arbitrary max_length