summaryrefslogtreecommitdiff
path: root/httemplate/search/sql.html
diff options
context:
space:
mode:
Diffstat (limited to 'httemplate/search/sql.html')
-rw-r--r--httemplate/search/sql.html8
1 files changed, 7 insertions, 1 deletions
diff --git a/httemplate/search/sql.html b/httemplate/search/sql.html
index b28c045d1..5f64ebc28 100644
--- a/httemplate/search/sql.html
+++ b/httemplate/search/sql.html
@@ -1,7 +1,13 @@
-<%= include( 'elements/search.html',
+<% include( 'elements/search.html',
'title' => 'Query Results',
'name' => 'rows',
'query' => 'SELECT '. ( $cgi->param('sql')
|| eidiot('Empty query') ),
)
%>
+<%init>
+
+die "access denied"
+ unless $FS::CurrentUser::CurrentUser->access_right('Raw SQL');
+
+</%init>