fix: add authorization check for Roles link in navbar

Only show Roles link in Settings dropdown for users with admin
permissions, preventing unauthorized access attempts.
This commit is contained in:
Moritz 2026-01-08 14:25:29 +01:00
parent 32296625fe
commit 59d656a07c
Signed by: moritz
GPG key ID: 1020A035E5DD0824

View file

@ -7,6 +7,7 @@ defmodule MvWeb.Layouts.Navbar do
use MvWeb, :verified_routes
alias Mv.Membership
import MvWeb.Authorization
attr :current_user, :map,
required: true,
@ -33,9 +34,11 @@ defmodule MvWeb.Layouts.Navbar do
<li>
<.link navigate="/settings">{gettext("Global Settings")}</.link>
</li>
<%= if can_access_page?(@current_user, "/admin/roles") do %>
<li>
<.link navigate="/admin/roles">{gettext("Roles")}</.link>
</li>
<% end %>
</ul>
</details>
</li>