X-Git-Url: http://wagnertech.de/gitweb/gitweb.cgi/timetracker.git/blobdiff_plain/21054f67875d0c0c947cc46fe438f407dbe94ee7..2352b1096ea3b8301f06d3e5b072022ae08a2f73:/mobile/projects.php diff --git a/mobile/projects.php b/mobile/projects.php index c35e738a..e3dc2f87 100644 --- a/mobile/projects.php +++ b/mobile/projects.php @@ -31,8 +31,7 @@ import('form.Form'); import('ttTeamHelper'); // Access checks. -// TODO: introduce view_own_projects right to keep access checks simple. -if (!(ttAccessAllowed('track_own_time') || ttAccessAllowed('track_time') || ttAccessAllowed('manage_projects'))) { +if (!(ttAccessAllowed('view_own_projects') || ttAccessAllowed('manage_projects'))) { header('Location: access_denied.php'); exit(); } @@ -40,10 +39,11 @@ if (MODE_PROJECTS != $user->tracking_mode && MODE_PROJECTS_AND_TASKS != $user->t header('Location: feature_disabled.php'); exit(); } +// End of access checks. if($user->can('manage_projects')) { - $active_projects = ttTeamHelper::getActiveProjects($user->team_id); - $inactive_projects = ttTeamHelper::getInactiveProjects($user->team_id); + $active_projects = ttTeamHelper::getActiveProjects($user->group_id); + $inactive_projects = ttTeamHelper::getInactiveProjects($user->group_id); } else $active_projects = $user->getAssignedProjects();