Index: openacs-4/packages/acs-tcl/tcl/request-processor-procs.tcl =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-tcl/tcl/request-processor-procs.tcl,v diff -u -N -r1.103 -r1.104 --- openacs-4/packages/acs-tcl/tcl/request-processor-procs.tcl 17 Oct 2010 21:06:09 -0000 1.103 +++ openacs-4/packages/acs-tcl/tcl/request-processor-procs.tcl 16 Feb 2011 19:03:01 -0000 1.104 @@ -699,7 +699,10 @@ ad_try { switch -glob -- [ad_conn extra_url] { admin/* { - permission::require_permission -object_id [ad_conn object_id] -privilege admin + # double check someone has not accidentally granted + # admin to public and require logins for all admin pages + auth::require_login + permission::require_permission -object_id [ad_conn object_id] -privilege admin } sitewide-admin/* { permission::require_permission -object_id [acs_lookup_magic_object security_context_root] -privilege admin