Merge pull request #11346 from ptibogxiv/patch-189

Fix add / delete contact access in order API
This commit is contained in:
Laurent Destailleur 2019-06-16 17:26:50 +02:00 committed by GitHub
commit a6c5dc9a46
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 17 additions and 22 deletions

View File

@ -415,21 +415,16 @@ class Orders extends DolibarrApi
*/ */
public function postContact($id, $contactid, $type) public function postContact($id, $contactid, $type)
{ {
if(!DolibarrApiAccess::$user->rights->commande->creer) { if (! DolibarrApiAccess::$user->rights->commande->creer) {
throw new RestException(401); throw new RestException(401);
}
$result = $this->commande->fetch($id);
if(!$result) {
throw new RestException(404, 'Order not found');
} }
if (!in_array($type, array('BILLING', 'SHIPPING', 'CUSTOMER'), true)) { $result = $this->commande->fetch($id);
throw new RestException(500, 'Availables types: BILLING, SHIPPING OR CUSTOMER'); if (! $result) {
throw new RestException(404, 'Order not found');
} }
if(!DolibarrApi::_checkAccessToResource('order', $this->commande->id)) { if (! DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login); throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
} }
@ -457,17 +452,16 @@ class Orders extends DolibarrApi
*/ */
public function deleteContact($id, $rowid) public function deleteContact($id, $rowid)
{ {
if(!DolibarrApiAccess::$user->rights->commande->creer) { if (! DolibarrApiAccess::$user->rights->commande->creer) {
throw new RestException(401); throw new RestException(401);
}
$result = $this->commande->fetch($id);
if(!$result) {
throw new RestException(404, 'Order not found');
} }
if(!DolibarrApi::_checkAccessToResource('order', $this->commande->id)) { $result = $this->commande->fetch($id);
if (! $result) {
throw new RestException(404, 'Order not found');
}
if (! DolibarrApi::_checkAccessToResource('commande', $this->commande->id)) {
throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login); throw new RestException(401, 'Access not allowed for login '.DolibarrApiAccess::$user->login);
} }

View File

@ -27,6 +27,7 @@ CREATE TABLE llx_bom_bom(
qty double(24,8), qty double(24,8),
efficiency double(8,4) DEFAULT 1, efficiency double(8,4) DEFAULT 1,
date_creation datetime NOT NULL, date_creation datetime NOT NULL,
date_valid datetime NOT NULL,
tms timestamp, tms timestamp,
date_valid datetime, date_valid datetime,
fk_user_creat integer NOT NULL, fk_user_creat integer NOT NULL,