X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=client_delete.php;h=a5f00656e592e67cb6fe614f98dc701d8d209873;hb=ed41335d63e71a11d30e92f4367106e9398adf9d;hp=b162ea844c9fc333dddca70282aa75102b37c17d;hpb=a0dd058ab6007cfc6a72713215a7f4abb96f1b45;p=timetracker.git diff --git a/client_delete.php b/client_delete.php index b162ea84..a5f00656 100644 --- a/client_delete.php +++ b/client_delete.php @@ -30,14 +30,22 @@ require_once('initialize.php'); import('form.Form'); import('ttClientHelper'); -// Access check. -if (!ttAccessAllowed('manage_clients') || !$user->isPluginEnabled('cl')) { +// Access checks. +if (!ttAccessAllowed('manage_clients')) { header('Location: access_denied.php'); exit(); } - +if (!$user->isPluginEnabled('cl')) { + header('Location: feature_disabled.php'); + exit(); +} $id = (int)$request->getParameter('id'); $client = ttClientHelper::getClient($id); +if (!$client) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. $client_to_delete = $client['name']; @@ -49,16 +57,13 @@ $form->addInput(array('type'=>'submit','name'=>'btn_delete','value'=>$i18n->get( $form->addInput(array('type'=>'submit','name'=>'btn_cancel','value'=>$i18n->get('button.cancel'))); if ($request->isPost()) { - if(ttClientHelper::getClient($id)) { - if ($request->getParameter('btn_delete')) { - if (ttClientHelper::delete($id, $request->getParameter('delete_client_entries'))) { - header('Location: clients.php'); - exit(); - } else - $err->add($i18n->get('error.db')); - } - } else - $err->add($i18n->get('error.db')); + if ($request->getParameter('btn_delete')) { + if (ttClientHelper::delete($id, $request->getParameter('delete_client_entries'))) { + header('Location: clients.php'); + exit(); + } else + $err->add($i18n->get('error.db')); + } if ($request->getParameter('btn_cancel')) { header('Location: clients.php');