diff --git a/src/moin/apps/admin/_tests/test_admin.py b/src/moin/apps/admin/_tests/test_admin.py index dcca5b773..fb40c20f6 100644 --- a/src/moin/apps/admin/_tests/test_admin.py +++ b/src/moin/apps/admin/_tests/test_admin.py @@ -1,4 +1,5 @@ # Copyright: 2011 Sam Toyer +# Copyright: 2024 MoinMoin:UlrichB # License: GNU GPL v2 (or any later version), see LICENSE.txt for details """ @@ -18,9 +19,9 @@ ({"endpoint": "admin.userprofile", "user_name": "DoesntExist"}, "403 FORBIDDEN", ("", "")), ({"endpoint": "admin.wikiconfig"}, "403 FORBIDDEN", ("", "")), ({"endpoint": "admin.wikiconfighelp"}, "403 FORBIDDEN", ("", "")), - ({"endpoint": "admin.interwikihelp"}, "200 OK", ("", "")), - ({"endpoint": "admin.highlighterhelp"}, "200 OK", ("", "")), - ({"endpoint": "admin.itemsize"}, "200 OK", ("", "")), + ({"endpoint": "admin.interwikihelp"}, "403 FORBIDDEN", ("", "")), + ({"endpoint": "admin.highlighterhelp"}, "403 FORBIDDEN", ("", "")), + ({"endpoint": "admin.itemsize"}, "403 FORBIDDEN", ("", "")), ), ) def test_admin(app, url_for_args, status, data): diff --git a/src/moin/apps/admin/views.py b/src/moin/apps/admin/views.py index 0a9ea34b9..aa8f4821e 100644 --- a/src/moin/apps/admin/views.py +++ b/src/moin/apps/admin/views.py @@ -75,6 +75,7 @@ def index(): @admin.route("/user") +@require_permission(SUPERUSER) def index_user(): return render_template( "user/index_user.html", @@ -359,6 +360,7 @@ def format_default(default): @admin.route("/highlighterhelp", methods=["GET"]) +@require_permission(SUPERUSER) def highlighterhelp(): """display a table with list of available Pygments lexers""" import pygments.lexers @@ -375,6 +377,7 @@ def highlighterhelp(): @admin.route("/interwikihelp", methods=["GET"]) +@require_permission(SUPERUSER) def interwikihelp(): """display a table with list of known interwiki names / urls""" headings = [_("InterWiki name"), _("URL")] @@ -383,6 +386,7 @@ def interwikihelp(): @admin.route("/itemsize", methods=["GET"]) +@require_permission(SUPERUSER) def itemsize(): """display a table with item sizes""" headings = [_("Size"), _("Item name")]