X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=predefined_expense_edit.php;h=3f0cb0c8c9dc5c9910a38c9799b0c06e9ad1b199;hb=67e827dacf08d8a55dff9118c82dd964f5da12c1;hp=7791b2440190ee9296cda48cec4fe8befbfa77bd;hpb=030d2c3ffbf8229cc945427e9e9f7704226effe1;p=timetracker.git diff --git a/predefined_expense_edit.php b/predefined_expense_edit.php index 7791b244..3f0cb0c8 100644 --- a/predefined_expense_edit.php +++ b/predefined_expense_edit.php @@ -39,14 +39,18 @@ if (!$user->isPluginEnabled('ex')) { header('Location: feature_disabled.php'); exit(); } - $predefined_expense_id = (int) $request->getParameter('id'); +$predefined_expense = ttPredefinedExpenseHelper::get($predefined_expense_id); +if (!$predefined_expense) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. if ($request->isPost()) { $cl_name = trim($request->getParameter('name')); $cl_cost = trim($request->getParameter('cost')); } else { - $predefined_expense = ttPredefinedExpenseHelper::get($predefined_expense_id); $cl_name = $predefined_expense['name']; $cl_cost = $predefined_expense['cost']; } @@ -64,7 +68,6 @@ if ($request->isPost()) { if ($err->no()) { if (ttPredefinedExpenseHelper::update(array( 'id' => $predefined_expense_id, - 'team_id' => $user->team_id, 'name' => $cl_name, 'cost' => $cl_cost))) { header('Location: predefined_expenses.php');