X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=predefined_expense_edit.php;h=3f0cb0c8c9dc5c9910a38c9799b0c06e9ad1b199;hb=cdd27c2b163122cb6e2169851019721b3382abd7;hp=ab2299c0a14abf63b2fc5af9ddcf5526750d9ee6;hpb=07ee49d8208cc8308a167487f010e4b919555e03;p=timetracker.git diff --git a/predefined_expense_edit.php b/predefined_expense_edit.php index ab2299c0..3f0cb0c8 100644 --- a/predefined_expense_edit.php +++ b/predefined_expense_edit.php @@ -39,14 +39,18 @@ if (!$user->isPluginEnabled('ex')) { header('Location: feature_disabled.php'); exit(); } - $predefined_expense_id = (int) $request->getParameter('id'); +$predefined_expense = ttPredefinedExpenseHelper::get($predefined_expense_id); +if (!$predefined_expense) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. if ($request->isPost()) { $cl_name = trim($request->getParameter('name')); $cl_cost = trim($request->getParameter('cost')); } else { - $predefined_expense = ttPredefinedExpenseHelper::get($predefined_expense_id); $cl_name = $predefined_expense['name']; $cl_cost = $predefined_expense['cost']; }