Fix permission issue when changing the url manually
This commit is contained in:
@@ -269,12 +269,17 @@ abstract class Base extends \Core\Base
|
||||
*/
|
||||
protected function getTask()
|
||||
{
|
||||
$project_id = $this->request->getIntegerParam('project_id');
|
||||
$task = $this->taskFinder->getDetails($this->request->getIntegerParam('task_id'));
|
||||
|
||||
if (empty($task)) {
|
||||
$this->notfound();
|
||||
}
|
||||
|
||||
if ($project_id !== 0 && $project_id != $task['project_id']) {
|
||||
$this->forbidden();
|
||||
}
|
||||
|
||||
return $task;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user