Fix security permissions to edit/delete time spent
This commit is contained in:
parent
380b61a0e9
commit
3a2f44adac
@ -128,7 +128,7 @@ if ($action == 'addtimespent' && $user->rights->projet->lire)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($action == 'updateline' && ! $_POST["cancel"] && $user->rights->projet->creer)
|
if ($action == 'updateline' && ! $_POST["cancel"] && $user->rights->projet->lire)
|
||||||
{
|
{
|
||||||
$error=0;
|
$error=0;
|
||||||
|
|
||||||
@ -141,6 +141,7 @@ if ($action == 'updateline' && ! $_POST["cancel"] && $user->rights->projet->cree
|
|||||||
if (! $error)
|
if (! $error)
|
||||||
{
|
{
|
||||||
$object->fetch($id, $ref);
|
$object->fetch($id, $ref);
|
||||||
|
// TODO Check that ($task_time->fk_user == $user->id || in_array($task_time->fk_user, $childids))
|
||||||
|
|
||||||
$object->timespent_id = $_POST["lineid"];
|
$object->timespent_id = $_POST["lineid"];
|
||||||
$object->timespent_note = $_POST["timespent_note_line"];
|
$object->timespent_note = $_POST["timespent_note_line"];
|
||||||
@ -175,9 +176,10 @@ if ($action == 'updateline' && ! $_POST["cancel"] && $user->rights->projet->cree
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($action == 'confirm_delete' && $confirm == "yes" && $user->rights->projet->creer)
|
if ($action == 'confirm_delete' && $confirm == "yes" && $user->rights->projet->lire)
|
||||||
{
|
{
|
||||||
$object->fetchTimeSpent($_GET['lineid']);
|
$object->fetchTimeSpent($_GET['lineid']);
|
||||||
|
// TODO Check that ($task_time->fk_user == $user->id || in_array($task_time->fk_user, $childids))
|
||||||
$result = $object->delTimeSpent($user);
|
$result = $object->delTimeSpent($user);
|
||||||
|
|
||||||
if ($result < 0)
|
if ($result < 0)
|
||||||
@ -585,6 +587,8 @@ if (($id > 0 || ! empty($ref)) || $projectidforalltimes > 0)
|
|||||||
|
|
||||||
$tasktmp = new Task($db);
|
$tasktmp = new Task($db);
|
||||||
|
|
||||||
|
$childids = $user->getAllChildIds();
|
||||||
|
|
||||||
$total = 0;
|
$total = 0;
|
||||||
$totalvalue = 0;
|
$totalvalue = 0;
|
||||||
foreach ($tasks as $task_time)
|
foreach ($tasks as $task_time)
|
||||||
@ -688,17 +692,20 @@ if (($id > 0 || ! empty($ref)) || $projectidforalltimes > 0)
|
|||||||
print '<br>';
|
print '<br>';
|
||||||
print '<input type="submit" class="button" name="cancel" value="'.$langs->trans('Cancel').'">';
|
print '<input type="submit" class="button" name="cancel" value="'.$langs->trans('Cancel').'">';
|
||||||
}
|
}
|
||||||
else if ($user->rights->projet->creer)
|
else if ($user->rights->projet->lire) // Read project and enter time consumed on assigned tasks
|
||||||
{
|
{
|
||||||
print ' ';
|
if ($task_time->fk_user == $user->id || in_array($task_time->fk_user, $childids))
|
||||||
print '<a href="'.$_SERVER["PHP_SELF"].'?'.($projectidforalltimes?'projectid='.$projectidforalltimes.'&':'').'id='.$task_time->fk_task.'&action=editline&lineid='.$task_time->rowid.($withproject?'&withproject=1':'').'">';
|
{
|
||||||
print img_edit();
|
print ' ';
|
||||||
print '</a>';
|
print '<a href="'.$_SERVER["PHP_SELF"].'?'.($projectidforalltimes?'projectid='.$projectidforalltimes.'&':'').'id='.$task_time->fk_task.'&action=editline&lineid='.$task_time->rowid.($withproject?'&withproject=1':'').'">';
|
||||||
|
print img_edit();
|
||||||
|
print '</a>';
|
||||||
|
|
||||||
print ' ';
|
print ' ';
|
||||||
print '<a href="'.$_SERVER["PHP_SELF"].'?'.($projectidforalltimes?'projectid='.$projectidforalltimes.'&':'').'id='.$task_time->fk_task.'&action=deleteline&lineid='.$task_time->rowid.($withproject?'&withproject=1':'').'">';
|
print '<a href="'.$_SERVER["PHP_SELF"].'?'.($projectidforalltimes?'projectid='.$projectidforalltimes.'&':'').'id='.$task_time->fk_task.'&action=deleteline&lineid='.$task_time->rowid.($withproject?'&withproject=1':'').'">';
|
||||||
print img_delete();
|
print img_delete();
|
||||||
print '</a>';
|
print '</a>';
|
||||||
|
}
|
||||||
}
|
}
|
||||||
print '</td>';
|
print '</td>';
|
||||||
|
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user