check for access on document in mytasks and view->menutasks (Ticket #88)

previously documents where listed, even if the user had no access
This commit is contained in:
Uwe Steinmann 2016-11-14 08:38:12 +01:00
parent a560035482
commit 718762d284

View File

@ -535,27 +535,39 @@ switch($command) {
$resArr = $dms->getDocumentList('ApproveByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$approvals[] = $res['id'];
}
}
}
$resArr = $dms->getDocumentList('ReviewByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$reviews[] = $res['id'];
}
}
}
$resArr = $dms->getDocumentList('ReceiptByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$receipts[] = $res['id'];
}
}
}
$resArr = $dms->getDocumentList('ReviseByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$revisions[] = $res['id'];
}
}
}
$content = $view->menuTasks(array('review'=>$reviews, 'approval'=>$approvals, 'receipt'=>$receipts, 'revision'=>$revisions));
break;
case 'mainclipboard':
@ -871,27 +883,39 @@ switch($command) {
$resArr = $dms->getDocumentList('ApproveByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$approvals[] = array('id'=>$res['id'], 'name'=>$res['name']);
}
}
}
$resArr = $dms->getDocumentList('ReviewByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$reviews[] = array('id'=>$res['id'], 'name'=>$res['name']);
}
}
}
$resArr = $dms->getDocumentList('ReceiptByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$receipts[] = array('id'=>$res['id'], 'name'=>$res['name']);
}
}
}
$resArr = $dms->getDocumentList('ReviseByMe', $user);
if($resArr) {
foreach ($resArr as $res) {
$document = $dms->getDocument($res["id"]);
if($document->getAccessMode($user) >= M_READ && $document->getLatestContent()) {
$revisions[] = array('id'=>$res['id'], 'name'=>$res['name']);
}
}
}
header('Content-Type: application/json');
echo json_encode(array('error'=>0, 'data'=>array('review'=>$reviews, 'approval'=>$approvals, 'receipt'=>$receipts, 'revision'=>$revisions), 'processing_time'=>microtime(true)-$startts));
}