From d84fbd3987192e9bece5fc074dd7507dd1e2c7b7 Mon Sep 17 00:00:00 2001 From: mark Date: Mon, 14 Dec 2009 01:41:29 +0000 Subject: Add access right to view attachments --- httemplate/view/cust_main.cgi | 6 ++++-- httemplate/view/cust_main/attachments.html | 2 +- 2 files changed, 5 insertions(+), 3 deletions(-) (limited to 'httemplate/view') diff --git a/httemplate/view/cust_main.cgi b/httemplate/view/cust_main.cgi index 08d99d8e8..76f5a517e 100755 --- a/httemplate/view/cust_main.cgi +++ b/httemplate/view/cust_main.cgi @@ -153,16 +153,18 @@ Comments ) %> % } +% if( $curuser->access_right('View attachments') ) { <% include('cust_main/attachments.html', 'custnum' => $cust_main->custnum ) %> -% if($cgi->param('show_deleted')) { +% if ($cgi->param('show_deleted')) { ">(Show active attachments) -% } +% } % elsif($curuser->access_right('View deleted attachments')) { ">(Show deleted attachments) +% } % }
diff --git a/httemplate/view/cust_main/attachments.html b/httemplate/view/cust_main/attachments.html index dbb29a7c0..b16a81eae 100755 --- a/httemplate/view/cust_main/attachments.html +++ b/httemplate/view/cust_main/attachments.html @@ -109,7 +109,7 @@ my $conf = new FS::Conf; my $curuser = $FS::CurrentUser::CurrentUser; - +die "access denied" if !$curuser->access_right('View attachments'); my(%opt) = @_; my $custnum = $opt{'custnum'}; -- cgit v1.2.1