[-] BO : fixed right permissions for new tabs #PSCFV-3640
This commit is contained in:
+5
-12
@@ -117,27 +117,20 @@ class TabCore extends ObjectModel
|
|||||||
$context = Context::getContext();
|
$context = Context::getContext();
|
||||||
if (!$context->employee || !$context->employee->id_profile)
|
if (!$context->employee || !$context->employee->id_profile)
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
/* Profile selection */
|
/* Profile selection */
|
||||||
$profiles = Db::getInstance()->executeS('
|
$profiles = Db::getInstance()->executeS('SELECT `id_profile` FROM '._DB_PREFIX_.'profile WHERE `id_profile` != 1');
|
||||||
SELECT `id_profile`
|
|
||||||
FROM '._DB_PREFIX_.'profile
|
|
||||||
WHERE `id_profile` != 1
|
|
||||||
');
|
|
||||||
if (!$profiles || empty($profiles))
|
if (!$profiles || empty($profiles))
|
||||||
return false;
|
return true;
|
||||||
|
|
||||||
/* Query definition */
|
/* Query definition */
|
||||||
// note : insert ignore should be avoided
|
$query = 'REPLACE INTO `'._DB_PREFIX_.'access` (`id_profile`, `id_tab`, `view`, `add`, `edit`, `delete`) VALUES ';
|
||||||
$query = 'INSERT IGNORE INTO `'._DB_PREFIX_.'access` (`id_profile`, `id_tab`, `view`, `add`, `edit`, `delete`) VALUES ';
|
|
||||||
// default admin
|
|
||||||
$query .= '(1, '.(int)$id_tab.', 1, 1, 1, 1),';
|
$query .= '(1, '.(int)$id_tab.', 1, 1, 1, 1),';
|
||||||
|
|
||||||
foreach ($profiles as $profile)
|
foreach ($profiles as $profile)
|
||||||
{
|
{
|
||||||
// no cast needed for profile[id_profile], which cames from db
|
|
||||||
// And we disable all profile but current one
|
|
||||||
$rights = $profile['id_profile'] == $context->employee->id_profile ? 1 : 0;
|
$rights = $profile['id_profile'] == $context->employee->id_profile ? 1 : 0;
|
||||||
$query .= '('.$profile['id_profile'].', '.(int)$id_tab.', '.$rights.', '.$rights.', '.$rights.', '.$rights.'),';
|
$query .= '('.(int)$profile['id_profile'].', '.(int)$id_tab.', '.(int)$rights.', '.(int)$rights.', '.(int)$rights.', '.(int)$rights.'),';
|
||||||
}
|
}
|
||||||
$query = trim($query, ', ');
|
$query = trim($query, ', ');
|
||||||
return Db::getInstance()->execute($query);
|
return Db::getInstance()->execute($query);
|
||||||
|
|||||||
Reference in New Issue
Block a user