diff --git a/out/out.RemoveFolder.php b/out/out.RemoveFolder.php index 4c912b958..df96fc2b4 100644 --- a/out/out.RemoveFolder.php +++ b/out/out.RemoveFolder.php @@ -43,6 +43,10 @@ if (!is_object($folder)) { UI::exitError(getMLText("folder_title", array("foldername" => getMLText("invalid_folder_id"))),getMLText("invalid_folder_id")); } +if (!$accessop->check_view_access($view, $_GET)) { + UI::exitError(getMLText("folder_title", array("foldername" => htmlspecialchars($folder->getName()))),getMLText("access_denied")); +} + if ($folder->getID() == $settings->_rootFolderID || !$folder->getParent()) { UI::exitError(getMLText("folder_title", array("foldername" => htmlspecialchars($folder->getName()))),getMLText("cannot_rm_root")); }