298077582b
Ref #2061 - Add canThis permission checks to settings api calls - Add strict rules about accessing core settings without internal: true - Omit core settings in browse() call unless internal: true - Update unit tests to call api.settings with contexts - Add a couple unit tests for new scenarios - Update all api.settings calls in the app to call with internal context - Re-arrange permissions.init in server startup so config.theme.update can access settings without permissions error |
||
---|---|---|
.. | ||
dependencies.js | ||
index.js | ||
loader.js | ||
permissions.js | ||
proxy.js | ||
sandbox.js |