Author: danydb
Date: 2011-11-24 15:45:36 +0100 (Thu, 24 Nov 2011)
New Revision: 4472
Modified:
phpcompta/trunk/html/ajax_misc.php
Log:
#472 protect ajax for stock and ANCODS
Modified: phpcompta/trunk/html/ajax_misc.php
===================================================================
--- phpcompta/trunk/html/ajax_misc.php 2011-11-24 14:31:09 UTC (rev 4471)
+++ phpcompta/trunk/html/ajax_misc.php 2011-11-24 14:45:36 UTC (rev 4472)
@@ -66,9 +66,11 @@
switch ($op)
{
case "remove_anc":
+ if ($user->check_module('ANCODS') == 0) exit();
$cn->exec_sql("delete from operation_analytique where
oa_group=$1", array($_GET['oa']));
break;
case "rm_stock":
+ if ($user->check_module('STOCK') == 0) exit();
require_once('constant.security.php');
$cn->exec_sql('delete from stock_goods where sg_id=$1',
array($s_id));
$html = escape_xml($s_id);
_______________________________________________
Phpcompta-dev mailing list
[email protected]
https://lists.nongnu.org/mailman/listinfo/phpcompta-dev