add check_view_access

This commit is contained in:
Uwe Steinmann 2021-02-24 10:23:01 +01:00
parent 2fd21b9792
commit 826a6ae109

View File

@ -43,6 +43,10 @@ if (!is_object($folder)) {
UI::exitError(getMLText("folder_title", array("foldername" => getMLText("invalid_folder_id"))),getMLText("invalid_folder_id")); UI::exitError(getMLText("folder_title", array("foldername" => getMLText("invalid_folder_id"))),getMLText("invalid_folder_id"));
} }
if (!$accessop->check_view_access($view, $_GET)) {
UI::exitError(getMLText("folder_title", array("foldername" => htmlspecialchars($folder->getName()))),getMLText("access_denied"));
}
if ($folder->getID() == $settings->_rootFolderID || !$folder->getParent()) { if ($folder->getID() == $settings->_rootFolderID || !$folder->getParent()) {
UI::exitError(getMLText("folder_title", array("foldername" => htmlspecialchars($folder->getName()))),getMLText("cannot_rm_root")); UI::exitError(getMLText("folder_title", array("foldername" => htmlspecialchars($folder->getName()))),getMLText("cannot_rm_root"));
} }