@ -196,7 +196,7 @@ public class UserModule extends BaseHandler implements UserHelper {
@@ -196,7 +196,7 @@ public class UserModule extends BaseHandler implements UserHelper {
userId=Long.parseLong(head);
DbUsereditedUser=(DbUser)users.load(userId);
if(!(requestingUser.get()instanceofDbUserdbUser)||!dbUser.permissions().contains(UPDATE_USERS))returnsendContent(ex,HTTP_FORBIDDEN,"You are not allowed to update user "+editedUser.name());
if(!(requestingUser.get()instanceofDbUserdbUser)||!(dbUser.id()==userId||dbUser.permissions().contains(UPDATE_USERS)))returnsendContent(ex,HTTP_FORBIDDEN,"You are not allowed to update user "+editedUser.name());