Ghost/core/server/controllers
Jacob Gable 298077582b ACL and strict rules for Settings API
Ref #2061

- Add canThis permission checks to settings api calls
- Add strict rules about accessing core settings without internal: true
- Omit core settings in browse() call unless internal: true
- Update unit tests to call api.settings with contexts
- Add a couple unit tests for new scenarios
- Update all api.settings calls in the app to call with internal context
- Re-arrange permissions.init in server startup so config.theme.update
can access settings without permissions error
2014-05-07 10:56:03 -05:00
..
admin.js Proper endpoints for persistent notifications 2014-05-06 00:05:14 +02:00
frontend.js ACL and strict rules for Settings API 2014-05-07 10:56:03 -05:00