Skip to content
Snippets Groups Projects
Commit d6bec7a7 authored by Marius Cramer's avatar Marius Cramer
Browse files

- fixed access check in client templates and mail content filters

parent bd12aad9
No related branches found
No related tags found
1 merge request!245Stable 3.0.5
...@@ -44,7 +44,7 @@ require_once '../../lib/app.inc.php'; ...@@ -44,7 +44,7 @@ require_once '../../lib/app.inc.php';
//* Check permissions for module //* Check permissions for module
$app->auth->check_module_permissions('client'); $app->auth->check_module_permissions('client');
if(!$_SESSION["s"]["user"]["typ"] == 'admin') die('Client-Templates are for Admins only.'); if($_SESSION["s"]["user"]["typ"] != 'admin' && !$app->auth->has_clients($_SESSION['s']['user']['userid'])) die('Client-Templates are for Admins and Resellers only.');
$app->uses('tpl,tform'); $app->uses('tpl,tform');
$app->load('tform_actions'); $app->load('tform_actions');
......
...@@ -43,7 +43,7 @@ require_once '../../lib/app.inc.php'; ...@@ -43,7 +43,7 @@ require_once '../../lib/app.inc.php';
//* Check permissions for module //* Check permissions for module
$app->auth->check_module_permissions('client'); $app->auth->check_module_permissions('client');
if(!$_SESSION["s"]["user"]["typ"] == 'admin') die('Client-Templates are only for Admins.'); if($_SESSION["s"]["user"]["typ"] != 'admin' && !$app->auth->has_clients($_SESSION['s']['user']['userid'])) die('Client-Templates are for Admins and Resellers only.');
// Loading classes // Loading classes
$app->uses('tpl,tform,tform_actions'); $app->uses('tpl,tform,tform_actions');
......
...@@ -41,7 +41,7 @@ $list_def_file = "list/client_template.list.php"; ...@@ -41,7 +41,7 @@ $list_def_file = "list/client_template.list.php";
//* Check permissions for module //* Check permissions for module
$app->auth->check_module_permissions('client'); $app->auth->check_module_permissions('client');
if(!$_SESSION["s"]["user"]["typ"] == 'admin') die('Client-Templates are only for Admins.'); if($_SESSION["s"]["user"]["typ"] != 'admin' && !$app->auth->has_clients($_SESSION['s']['user']['userid'])) die('Client-Templates are for Admins and Resellers only.');
$app->uses('listform_actions'); $app->uses('listform_actions');
$app->listform_actions->SQLOrderBy = 'ORDER BY client_template.template_name'; $app->listform_actions->SQLOrderBy = 'ORDER BY client_template.template_name';
......
...@@ -44,7 +44,7 @@ require_once '../../lib/app.inc.php'; ...@@ -44,7 +44,7 @@ require_once '../../lib/app.inc.php';
//* Check permissions for module //* Check permissions for module
$app->auth->check_module_permissions('mail'); $app->auth->check_module_permissions('mail');
if(!$_SESSION["s"]["user"]["typ"] == 'admin') die('These Filters are only for Admins.'); if($_SESSION["s"]["user"]["typ"] != 'admin') die('These Filters are only for Admins.');
// Loading classes // Loading classes
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment