// Fix some BO access check on actions
This commit is contained in:
@@ -850,8 +850,6 @@ class AdminControllerCore extends Controller
|
|||||||
* @param string $token
|
* @param string $token
|
||||||
*/
|
*/
|
||||||
protected function processUpdateOptions($token)
|
protected function processUpdateOptions($token)
|
||||||
{
|
|
||||||
if ($this->tabAccess['edit'] === '1')
|
|
||||||
{
|
{
|
||||||
$this->beforeUpdateOptions();
|
$this->beforeUpdateOptions();
|
||||||
|
|
||||||
@@ -965,9 +963,6 @@ class AdminControllerCore extends Controller
|
|||||||
if (empty($this->errors))
|
if (empty($this->errors))
|
||||||
$this->confirmations[] = $this->_conf[6];
|
$this->confirmations[] = $this->_conf[6];
|
||||||
}
|
}
|
||||||
else
|
|
||||||
$this->errors[] = Tools::displayError('You do not have permission to edit here.');
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -1839,8 +1834,11 @@ class AdminControllerCore extends Controller
|
|||||||
/* Submit options list */
|
/* Submit options list */
|
||||||
else if (Tools::getValue('submitOptions'.$this->table) || Tools::getValue('submitOptions'))
|
else if (Tools::getValue('submitOptions'.$this->table) || Tools::getValue('submitOptions'))
|
||||||
{
|
{
|
||||||
$this->action = 'update_options';
|
|
||||||
$this->display = 'options';
|
$this->display = 'options';
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
|
$this->action = 'update_options';
|
||||||
|
else
|
||||||
|
$this->errors[] = Tools::displayError('You do not have permission to edit here.');
|
||||||
}
|
}
|
||||||
else if (Tools::isSubmit('submitFields') && $this->required_database && $this->tabAccess['add'] === '1' && $this->tabAccess['delete'] === '1')
|
else if (Tools::isSubmit('submitFields') && $this->required_database && $this->tabAccess['add'] === '1' && $this->tabAccess['delete'] === '1')
|
||||||
$this->action = 'update_fields';
|
$this->action = 'update_fields';
|
||||||
@@ -1848,15 +1846,25 @@ class AdminControllerCore extends Controller
|
|||||||
foreach ($this->bulk_actions as $bulk_action => $params)
|
foreach ($this->bulk_actions as $bulk_action => $params)
|
||||||
{
|
{
|
||||||
if (Tools::isSubmit('submitBulk'.$bulk_action.$this->table) || Tools::isSubmit('submitBulk'.$bulk_action))
|
if (Tools::isSubmit('submitBulk'.$bulk_action.$this->table) || Tools::isSubmit('submitBulk'.$bulk_action))
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$this->action = 'bulk'.$bulk_action;
|
$this->action = 'bulk'.$bulk_action;
|
||||||
$this->boxes = Tools::getValue($this->table.'Box');
|
$this->boxes = Tools::getValue($this->table.'Box');
|
||||||
|
}
|
||||||
|
else
|
||||||
|
$this->errors[] = Tools::displayError('You do not have permission to edit here.');
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
else if (Tools::isSubmit('submitBulk'))
|
else if (Tools::isSubmit('submitBulk'))
|
||||||
|
{
|
||||||
|
if ($this->tabAccess['edit'] === '1')
|
||||||
{
|
{
|
||||||
$this->action = 'bulk'.Tools::getValue('select_submitBulk');
|
$this->action = 'bulk'.Tools::getValue('select_submitBulk');
|
||||||
$this->boxes = Tools::getValue($this->table.'Box');
|
$this->boxes = Tools::getValue($this->table.'Box');
|
||||||
|
}
|
||||||
|
else
|
||||||
|
$this->errors[] = Tools::displayError('You do not have permission to edit here.');
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user