import('form.TableColumn');
import('ttRoleHelper');
-// Access check.
+// Access checks.
if (!ttAccessAllowed('manage_users')) {
header('Location: access_denied.php');
exit();
}
-
-// Get user id we are editing from the request.
-$user_id = (int) $request->getParameter('id');
-// Get user details.
-$user_details = ttUserHelper::getUserDetails($user_id);
-
-// Security checks.
-if (!$user_details || // No details.
- $user_details['team_id'] <> $user->team_id || // User not in team.
- $user_details['rank'] > $user->rank || // User has a bigger rank.
- ($user_details['rank'] == $user->rank && $user_details['id'] <> $user->id) // Same rank but not us.
- ) {
+$user_id = (int)$request->getParameter('id');
+$user_details = $user->getUser($user_id);
+if (!$user_details) {
header('Location: access_denied.php');
exit();
}
+// End of access checks.
if ($user->isPluginEnabled('cl'))
- $clients = ttTeamHelper::getActiveClients($user->team_id);
+ $clients = ttTeamHelper::getActiveClients($user->group_id);
-$projects = ttTeamHelper::getActiveProjects($user->team_id);
+$projects = ttTeamHelper::getActiveProjects($user->group_id);
$assigned_projects = array();
if ($request->isPost()) {
}
} // isPost
+$can_swap = false;
+if ($user->id == $user_id && $user->can('swap_roles')) {
+ $users_for_swap = ttTeamHelper::getUsersForSwap();
+ if (is_array($users_for_swap) && sizeof($users_for_swap) > 0)
+ $can_swap = true;
+}
+
$rates = ttProjectHelper::getRates($user_id);
$smarty->assign('rates', $rates);
$smarty->assign('auth_external', $auth->isPasswordExternal());
$smarty->assign('active_roles', $active_roles);
+$smarty->assign('can_swap', $can_swap);
$smarty->assign('forms', array($form->getName()=>$form->toArray()));
$smarty->assign('onload', 'onLoad="document.userForm.name.focus();handleClientControl();"');
$smarty->assign('user_id', $user_id);