+ return false;
+ }
+
+ // getRecordForFileView - retrieves a time record identified by its id for
+ // attachment view operation.
+ //
+ // It is different from getRecord, as we want users with appropriate rights
+ // to be able to see other users files, without changing "on behalf" user.
+ // For example, viewing reports for all users and their attached files
+ // from report links.
+ static function getRecordForFileView($id) {
+ // There are several possible situations:
+ //
+ // Record is ours. Check "view_own_reports" or "view_all_reports".
+ // Record is for the current on behalf user. Check "view_reports" or "view_all_reports".
+ // Record is for someone else. Check "view_reports" or "view_all_reports" and rank.
+ //
+ // It looks like the best way is to use 2 queries, obtain user_id first, then check rank.
+
+ global $user;
+
+ $group_id = $user->getGroup();
+ $org_id = $user->org_id;
+
+ $mdb2 = getConnection();
+
+ // Obtain user_id for the time record.
+ $sql = "select l.id, l.user_id, l.timesheet_id, l.invoice_id, l.approved from tt_log l ".
+ " where l.id = $id and l.group_id = $group_id and l.org_id = $org_id and l.status = 1";
+ $res = $mdb2->query($sql);
+ if (is_a($res, 'PEAR_Error')) return false;
+ if (!$res->numRows()) return false;