X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=predefined_expense_delete.php;h=d8fc057fcc14158d83af37ca9102a1cd3862131f;hb=HEAD;hp=9b4450325e3e1a9a99a0da02a2fe23d00f69d6f2;hpb=030d2c3ffbf8229cc945427e9e9f7704226effe1;p=timetracker.git diff --git a/predefined_expense_delete.php b/predefined_expense_delete.php index 9b445032..d8fc057f 100644 --- a/predefined_expense_delete.php +++ b/predefined_expense_delete.php @@ -39,9 +39,15 @@ if (!$user->isPluginEnabled('ex')) { header('Location: feature_disabled.php'); exit(); } - $cl_predefined_expense_id = (int)$request->getParameter('id'); $predefined_expense = ttPredefinedExpenseHelper::get($cl_predefined_expense_id); +if (!$predefined_expense) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. + + $predefined_expense_to_delete = $predefined_expense['name']; $form = new Form('predefinedExpenseDeleteForm'); @@ -51,12 +57,9 @@ $form->addInput(array('type'=>'submit','name'=>'btn_cancel','value'=>$i18n->get( if ($request->isPost()) { if ($request->getParameter('btn_delete')) { - if(ttPredefinedExpenseHelper::get($cl_predefined_expense_id)) { - if (ttPredefinedExpenseHelper::delete($cl_predefined_expense_id)) { - header('Location: predefined_expenses.php'); - exit(); - } else - $err->add($i18n->get('error.db')); + if (ttPredefinedExpenseHelper::delete($cl_predefined_expense_id)) { + header('Location: predefined_expenses.php'); + exit(); } else $err->add($i18n->get('error.db')); } elseif ($request->getParameter('btn_cancel')) {