From 0867c96f616046e7f095d41fe4fbb398442c82ae Mon Sep 17 00:00:00 2001 From: Artem Chernitsov Date: Wed, 29 Jun 2022 11:48:06 +0300 Subject: [PATCH] fix of recruitment module - checking file permissions --- htdocs/core/lib/files.lib.php | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/htdocs/core/lib/files.lib.php b/htdocs/core/lib/files.lib.php index 482831191d6..b8a40461bbc 100644 --- a/htdocs/core/lib/files.lib.php +++ b/htdocs/core/lib/files.lib.php @@ -2977,7 +2977,13 @@ function dol_check_secure_access_document($modulepart, $original_file, $entity, // Wrapping for import module $accessallowed = $user->rights->import->run; $original_file = $conf->import->dir_temp.'/'.$original_file; - } elseif ($modulepart == 'editor' && !empty($conf->fckeditor->dir_output)) { + } + elseif ($modulepart == 'recruitment' && !empty($conf->recruitment->dir_temp)){ + // Wrapping for recruitment module + $accessallowed = $user->rights->$modulepart->recruitmentjobposition->read; + $original_file = $conf->recruitment->dir_output .'/'. $original_file; + } + elseif ($modulepart == 'editor' && !empty($conf->fckeditor->dir_output)) { // Wrapping for wysiwyg editor $accessallowed = 1; $original_file = $conf->fckeditor->dir_output.'/'.$original_file;