Security fix for invoice view.
[timetracker.git] / invoice_view.php
index 7661d9c..4a6027a 100644 (file)
@@ -33,7 +33,7 @@ import('ttClientHelper');
 import('form.Form');
 
 // Access check.
-if (!ttAccessCheck(right_view_invoices) || !$user->isPluginEnabled('iv')) {
+if (!(ttAccessAllowed('manage_invoices') || ttAccessAllowed('view_own_invoices')) || !$user->isPluginEnabled('iv')) {
   header('Location: access_denied.php');
   exit();
 }