fix: require current password when admin changes their own password (#9238)

Fixes https://github.com/jellyfin/jellyfin/issues/9208
pull/9243/head
Claus Vium 2 years ago committed by GitHub
parent 29c1f54b57
commit e79f5d8226
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -277,7 +277,7 @@ namespace Jellyfin.Api.Controllers
} }
else else
{ {
if (!User.IsInRole(UserRoles.Administrator)) if (!User.IsInRole(UserRoles.Administrator) || User.GetUserId().Equals(userId))
{ {
var success = await _userManager.AuthenticateUser( var success = await _userManager.AuthenticateUser(
user.Username, user.Username,

Loading…
Cancel
Save