From 6c84b858eeb57b6eee9e7f3f3edd0f2301d7e9a6 Mon Sep 17 00:00:00 2001 From: Laurent Destailleur Date: Thu, 8 Apr 2021 18:51:42 +0200 Subject: [PATCH] Fix #yogosha5832 --- htdocs/bom/class/api_boms.class.php | 4 ++++ htdocs/mrp/class/api_mos.class.php | 4 ++++ 2 files changed, 8 insertions(+) diff --git a/htdocs/bom/class/api_boms.class.php b/htdocs/bom/class/api_boms.class.php index b0f536140dd..1fe104987a3 100644 --- a/htdocs/bom/class/api_boms.class.php +++ b/htdocs/bom/class/api_boms.class.php @@ -99,6 +99,10 @@ class Boms extends DolibarrApi { global $db, $conf; + if (!DolibarrApiAccess::$user->rights->bom->read) { + throw new RestException(401); + } + $obj_ret = array(); $tmpobject = new BOM($this->db); diff --git a/htdocs/mrp/class/api_mos.class.php b/htdocs/mrp/class/api_mos.class.php index 281ec0fb731..48f93976d29 100644 --- a/htdocs/mrp/class/api_mos.class.php +++ b/htdocs/mrp/class/api_mos.class.php @@ -98,6 +98,10 @@ class Mos extends DolibarrApi { global $db, $conf; + if (!DolibarrApiAccess::$user->rights->mrp->read) { + throw new RestException(401); + } + $obj_ret = array(); $tmpobject = new Mo($this->db);