diff --git a/webapp/controller/UserController.class.php b/webapp/controller/UserController.class.php index 9eb05681..fe7fc626 100644 --- a/webapp/controller/UserController.class.php +++ b/webapp/controller/UserController.class.php @@ -810,6 +810,13 @@ class UserController extends BaseAuthedController { $oldUser = User::findByAddress($address); if ($oldUser) { if ($oldUser['account_id'] != myself()->_getAccountId()) { + if (!phpcommon\isSameSeriesAccount( + $oldUser['account_id'], + myself()->_getAccountId() + )) { + myself()->_rspErr(1, 'is not SameSeriesAccount'); + return; + } User::updateOther( $oldUser['account_id'], array(