SECURITY: Move 'UserGetRights' call before application of Session::getAllowedUserRights()