X-Git-Url: http://git.freeside.biz/gitweb/?a=blobdiff_plain;f=httemplate%2Fmisc%2Fprocess%2Fcacti_graphs.cgi;h=a4df722883bd0628ecff134761a03896c2e7aec1;hb=d2b55d07a9e6e64a38877136d7974ab93e14f1ed;hp=160b1ad852b2b61b0af87fb06d338567aaf36d0f;hpb=d9db63d82fce670cc3c21f86e577dd99c3d14028;p=freeside.git diff --git a/httemplate/misc/process/cacti_graphs.cgi b/httemplate/misc/process/cacti_graphs.cgi index 160b1ad85..a4df72288 100644 --- a/httemplate/misc/process/cacti_graphs.cgi +++ b/httemplate/misc/process/cacti_graphs.cgi @@ -1,6 +1,25 @@ <% $server->process %> <%init> +die "access denied" + unless $FS::CurrentUser::CurrentUser->access_right('View customer services'); + +# false laziness with view/elements/svc_Common.html +# only doing this to check agent access, don't actually use $svc_x +my %param = $cgi->param('arg'); +my $svcnum = $param{'svcnum'}; +my $svc_x = qsearchs({ + 'select' => 'svc_broadband.*', + 'table' => 'svc_broadband', + 'addl_from' => ' LEFT JOIN cust_svc USING ( svcnum ) '. + ' LEFT JOIN cust_pkg USING ( pkgnum ) '. + ' LEFT JOIN cust_main USING ( custnum ) ', + 'hashref' => { 'svcnum' => $svcnum }, + 'extra_sql' => ' AND '. $FS::CurrentUser::CurrentUser->agentnums_sql( + 'null_right' => 'View/link unlinked services' + ), +}) or die "Unknown svcnum $svcnum in svc_broadband table\n"; + my $server = FS::UI::Web::JSRPC->new('FS::part_export::cacti::process_graphs', $cgi);