X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=invoice_delete.php;h=ffdcf2c17cf134c6a2fd8e241d28101806daecc4;hb=35727570b2274aca4f0d816372dabfc93d00cf2d;hp=41f7c1901093da62be5e7375e540b191a2eafd50;hpb=3ad790a3d4bc23cb23f7ee072171ca6ef987eb56;p=timetracker.git diff --git a/invoice_delete.php b/invoice_delete.php index 41f7c190..ffdcf2c1 100644 --- a/invoice_delete.php +++ b/invoice_delete.php @@ -30,24 +30,33 @@ require_once('initialize.php'); import('form.Form'); import('ttInvoiceHelper'); -// Access check. -if (!ttAccessCheck(right_manage_team) || !$user->isPluginEnabled('iv')) { +// Access checks. +if (!ttAccessAllowed('manage_invoices')) { header('Location: access_denied.php'); exit(); } - +if (!$user->isPluginEnabled('iv')) { + header('Location: feature_disabled.php'); + exit(); +} $cl_invoice_id = (int)$request->getParameter('id'); $invoice = ttInvoiceHelper::getInvoice($cl_invoice_id); +if (!$invoice) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. + $invoice_to_delete = $invoice['name']; $form = new Form('invoiceDeleteForm'); $form->addInput(array('type'=>'hidden','name'=>'id','value'=>$cl_invoice_id)); $form->addInput(array('type'=>'combobox', 'name'=>'delete_invoice_entries', - 'data'=>array('0'=>$i18n->getKey('dropdown.do_not_delete'),'1'=>$i18n->getKey('dropdown.delete')), + 'data'=>array('0'=>$i18n->get('dropdown.do_not_delete'),'1'=>$i18n->get('dropdown.delete')), )); -$form->addInput(array('type'=>'submit','name'=>'btn_delete','value'=>$i18n->getKey('label.delete'))); -$form->addInput(array('type'=>'submit','name'=>'btn_cancel','value'=>$i18n->getKey('button.cancel'))); +$form->addInput(array('type'=>'submit','name'=>'btn_delete','value'=>$i18n->get('label.delete'),'onclick'=>'return confirm_deleting_entries();')); +$form->addInput(array('type'=>'submit','name'=>'btn_cancel','value'=>$i18n->get('button.cancel'))); if ($request->isPost()) { if ($request->getParameter('btn_delete')) { @@ -56,9 +65,9 @@ if ($request->isPost()) { header('Location: invoices.php'); exit(); } else - $err->add($i18n->getKey('error.db')); + $err->add($i18n->get('error.db')); } else - $err->add($i18n->getKey('error.db')); + $err->add($i18n->get('error.db')); } elseif ($request->getParameter('btn_cancel')) { header('Location: invoices.php'); exit(); @@ -68,6 +77,6 @@ if ($request->isPost()) { $smarty->assign('invoice_to_delete', $invoice_to_delete); $smarty->assign('forms', array($form->getName()=>$form->toArray())); $smarty->assign('onload', 'onLoad="document.invoiceDeleteForm.btn_cancel.focus()"'); -$smarty->assign('title', $i18n->getKey('title.delete_invoice')); +$smarty->assign('title', $i18n->get('title.delete_invoice')); $smarty->assign('content_page_name', 'invoice_delete.tpl'); $smarty->display('index.tpl');