summaryrefslogtreecommitdiffstats
path: root/controller/itemcontroller.php
diff options
context:
space:
mode:
authorBernhard Posselt <dev@bernhard-posselt.com>2014-04-09 01:59:42 +0200
committerBernhard Posselt <dev@bernhard-posselt.com>2014-04-09 22:52:27 +0200
commit4637dcc4587ed0c3b1695568a3c8a3853d695c5d (patch)
treee1778a3ddbaa95568ab90c211d49925f4946d157 /controller/itemcontroller.php
parent6d365e8083ecf67212203fe86fd1e1bf2b4ac281 (diff)
migrate security annotations, please review
Diffstat (limited to 'controller/itemcontroller.php')
-rw-r--r--controller/itemcontroller.php28
1 files changed, 7 insertions, 21 deletions
diff --git a/controller/itemcontroller.php b/controller/itemcontroller.php
index a813d92ca..2dd919fed 100644
--- a/controller/itemcontroller.php
+++ b/controller/itemcontroller.php
@@ -53,9 +53,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function items(){
$userId = $this->api->getUserId();
@@ -94,9 +92,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function newItems() {
$userId = $this->api->getUserId();
@@ -132,9 +128,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function star(){
try {
@@ -149,9 +143,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function unstar(){
try {
@@ -174,9 +166,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function read(){
try {
@@ -191,9 +181,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function unread(){
try {
@@ -208,9 +196,7 @@ class ItemController extends Controller {
/**
- * @IsAdminExemption
- * @IsSubAdminExemption
- * @Ajax
+ * @NoAdminRequired
*/
public function readAll(){
$userId = $this->api->getUserId();