X-Git-Url: http://wagnertech.de/git?a=blobdiff_plain;f=project_delete.php;h=3b165a33d563827ab90ee395f44a5babf34ef6a1;hb=cdd2e058776a3d0dc9b6f32a2d5d33e4f9388491;hp=683dbc50c9d14cea9684c36d53c240c210815fb1;hpb=fd0872d9e582113346fa1e93557f370286c5c9f2;p=timetracker.git diff --git a/project_delete.php b/project_delete.php index 683dbc50..3b165a33 100644 --- a/project_delete.php +++ b/project_delete.php @@ -30,14 +30,23 @@ require_once('initialize.php'); import('form.Form'); import('ttProjectHelper'); -// Access check. -if (!ttAccessAllowed('manage_projects') || (MODE_PROJECTS != $user->tracking_mode && MODE_PROJECTS_AND_TASKS != $user->tracking_mode)) { +// Access checks. +if (!ttAccessAllowed('manage_projects')) { header('Location: access_denied.php'); exit(); } - +if (MODE_PROJECTS != $user->getTrackingMode() && MODE_PROJECTS_AND_TASKS != $user->getTrackingMode()) { + header('Location: feature_disabled.php'); + exit(); +} $cl_project_id = (int)$request->getParameter('id'); $project = ttProjectHelper::get($cl_project_id); +if (!$project) { + header('Location: access_denied.php'); + exit(); +} +// End of access checks. + $project_to_delete = $project['name']; $form = new Form('projectDeleteForm'); @@ -47,12 +56,9 @@ $form->addInput(array('type'=>'submit','name'=>'btn_cancel','value'=>$i18n->get( if ($request->isPost()) { if ($request->getParameter('btn_delete')) { - if(ttProjectHelper::get($cl_project_id)) { - if (ttProjectHelper::delete($cl_project_id)) { - header('Location: projects.php'); - exit(); - } else - $err->add($i18n->get('error.db')); + if (ttProjectHelper::delete($cl_project_id)) { + header('Location: projects.php'); + exit(); } else $err->add($i18n->get('error.db')); } elseif ($request->getParameter('btn_cancel')) {