X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=invoice_send.php;h=20c3c187015285a157d43cd76c4a95264a42944c;hb=995feb6c9e97991e5b9d9803fbc3c8a41ac48922;hp=f0e30bc4bfe83958571e5d54fb5797632a069999;hpb=4dcb88a76a3de466ee6116ae0852f53ba2b259a5;p=timetracker.git diff --git a/invoice_send.php b/invoice_send.php index f0e30bc4..20c3c187 100644 --- a/invoice_send.php +++ b/invoice_send.php @@ -40,14 +40,15 @@ if (!$user->isPluginEnabled('iv')) { header('Location: feature_disabled.php'); exit(); } - $cl_invoice_id = (int)$request->getParameter('id'); -$invoice = ttInvoiceHelper::getInvoice($cl_invoice_id); -$sc = new ttSysConfig($user->id); +$invoice = ttInvoiceHelper::getInvoice($cl_invoice_id); +if (!$invoice) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. -// Security check. -if (!$cl_invoice_id || !$invoice) - die ($i18n->get('error.sys')); +$sc = new ttSysConfig($user->id); if ($request->isPost()) { $cl_receiver = trim($request->getParameter('receiver'));