diff --git a/htdocs/user/param_ihm.php b/htdocs/user/param_ihm.php index b380c73e51c..b28c33b08a2 100644 --- a/htdocs/user/param_ihm.php +++ b/htdocs/user/param_ihm.php @@ -48,16 +48,16 @@ if ($_REQUEST["id"]) $socid=0; if ($user->societe_id > 0) $socid = $user->societe_id; $feature2 = (($socid && $user->rights->user->self->creer)?'':'user'); -if ($user->id == $_GET["id"]) // A user can always read its own card +if ($user->id == $_REQUEST["id"]) // A user can always read its own card { $feature2=''; $canreaduser=1; } -$result = restrictedArea($user, 'user', $_GET["id"], '', $feature2); +$result = restrictedArea($user, 'user', $_REQUEST["id"], '', $feature2); if ($user->id <> $_REQUEST["id"] && ! $canreaduser) accessforbidden(); -$id=isset($_GET["id"])?$_GET["id"]:$_POST["id"]; +$id=! empty($_GET["id"])?$_GET["id"]:$_POST["id"]; $dirtop = "../includes/menus/barre_top"; $dirleft = "../includes/menus/barre_left"; $dirtheme = "../theme"; @@ -167,7 +167,8 @@ if ($_GET["action"] == 'edit') $var=!$var; print '