Ajout de la permission "consulter tous les clients" dans le module commercial, afin
qu'un commercial puisse voir que les clients qui lui sont affectés.
This commit is contained in:
parent
4186e0db40
commit
96402a9dcc
@ -32,17 +32,17 @@ require("./pre.inc.php");
|
|||||||
|
|
||||||
if (!$user->rights->projet->lire) accessforbidden();
|
if (!$user->rights->projet->lire) accessforbidden();
|
||||||
|
|
||||||
$socid = ( is_numeric($_GET["socid"]) ? $_GET["socid"] : 0 );
|
$socidp = ( is_numeric($_GET["socid"]) ? $_GET["socid"] : 0 );
|
||||||
|
|
||||||
$title = $langs->trans("Projects");
|
$title = $langs->trans("Projects");
|
||||||
|
|
||||||
// Sécurité accés client
|
// Sécurité accés client
|
||||||
if ($user->societe_id > 0) $socid = $user->societe_id;
|
if ($user->societe_id > 0) $socidp = $user->societe_id;
|
||||||
|
|
||||||
if ($socid > 0)
|
if ($socidp > 0)
|
||||||
{
|
{
|
||||||
$soc = new Societe($db);
|
$soc = new Societe($db);
|
||||||
$soc->fetch($socid);
|
$soc->fetch($socidp);
|
||||||
$title .= ' (<a href="liste.php">'.$soc->nom.'</a>)';
|
$title .= ' (<a href="liste.php">'.$soc->nom.'</a>)';
|
||||||
}
|
}
|
||||||
|
|
||||||
@ -70,11 +70,14 @@ llxHeader();
|
|||||||
|
|
||||||
$sql = "SELECT p.rowid as projectid, p.ref, p.title, ".$db->pdate("p.dateo")." as do";
|
$sql = "SELECT p.rowid as projectid, p.ref, p.title, ".$db->pdate("p.dateo")." as do";
|
||||||
$sql .= " , s.nom, s.idp, s.client";
|
$sql .= " , s.nom, s.idp, s.client";
|
||||||
|
if (!$user->rights->commercial->client->voir && !$socidp) $sql .= ", sc.fk_soc, sc.fk_user";
|
||||||
$sql .= " FROM ".MAIN_DB_PREFIX."societe as s, ".MAIN_DB_PREFIX."projet as p";
|
$sql .= " FROM ".MAIN_DB_PREFIX."societe as s, ".MAIN_DB_PREFIX."projet as p";
|
||||||
|
if (!$user->rights->commercial->client->voir && !$socidp) $sql .= ", ".MAIN_DB_PREFIX."societe_commerciaux as sc";
|
||||||
$sql .= " WHERE p.fk_soc = s.idp";
|
$sql .= " WHERE p.fk_soc = s.idp";
|
||||||
if ($socid)
|
if (!$user->rights->commercial->client->voir && !$socidp) $sql .= " AND s.idp = sc.fk_soc AND sc.fk_user = " .$user->id;
|
||||||
|
if ($socidp)
|
||||||
{
|
{
|
||||||
$sql .= " AND s.idp = ".$socid;
|
$sql .= " AND s.idp = ".$socidp;
|
||||||
}
|
}
|
||||||
if ($_GET["search_ref"])
|
if ($_GET["search_ref"])
|
||||||
{
|
{
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user