From 388a13abb850dedde617e47d5b798db3195bece2 Mon Sep 17 00:00:00 2001
From: Jonathan Rose <jrose@digium.com>
Date: Thu, 4 Sep 2014 20:39:34 +0000
Subject: [PATCH] Manager: Require read permission for SYSTEM in order to send
 FullyBooted

Review: https://reviewboard.asterisk.org/r/3969/
........

Merged revisions 422584 from http://svn.asterisk.org/svn/asterisk/branches/1.8


git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/11@422625 65c4cc65-6c06-0410-ace0-fbb531ad65f3
---
 main/manager.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/main/manager.c b/main/manager.c
index 8c44f7cbfb..5f976afdcc 100644
--- a/main/manager.c
+++ b/main/manager.c
@@ -3317,6 +3317,7 @@ static int action_login(struct mansession *s, const struct message *m)
 	}
 	astman_send_ack(s, m, "Authentication accepted");
 	if ((s->session->send_events & EVENT_FLAG_SYSTEM)
+		&& (s->session->readperm & EVENT_FLAG_SYSTEM)
 		&& ast_test_flag(&ast_options, AST_OPT_FLAG_FULLY_BOOTED)) {
 		struct ast_str *auth = ast_str_alloca(80);
 		const char *cat_str = authority_to_str(EVENT_FLAG_SYSTEM, &auth);
-- 
GitLab