Security: gate and client-scope the client overview record pages

This commit is contained in:
johnnyq
2026-08-27 15:27:55 -04:00
parent 4e1d72e06d
commit 32811fd1d2
4 changed files with 14 additions and 0 deletions

View File

@@ -11,6 +11,9 @@ if (isset($_GET['client_id'])) {
$client_url = '';
}
// Perms
enforceUserPermission('module_support');
if (isset($_GET['asset_id'])) {
$asset_id = intval($_GET['asset_id']);
@@ -28,6 +31,7 @@ if (isset($_GET['asset_id'])) {
LEFT JOIN locations ON asset_location_id = location_id
LEFT JOIN asset_interfaces ON interface_asset_id = asset_id AND interface_primary = 1
WHERE asset_id = $asset_id
" . clientScopeSql('asset_client_id') . "
$client_query
LIMIT 1
");

View File

@@ -11,6 +11,9 @@ if (isset($_GET['client_id'])) {
$client_url = '';
}
// Perms
enforceUserPermission('module_client');
if (isset($_GET['contact_id'])) {
$contact_id = intval($_GET['contact_id']);
@@ -23,6 +26,7 @@ if (isset($_GET['contact_id'])) {
LEFT JOIN locations ON location_id = contact_location_id
LEFT JOIN users ON user_id = contact_user_id
WHERE contact_id = $contact_id
" . clientScopeSql('contact_client_id') . "
$client_query
LIMIT 1
");

View File

@@ -31,6 +31,9 @@ if (isset($_GET['client_id'])) {
}
}
// Perms
enforceUserPermission('module_client');
// Tags Filter
if (isset($_GET['tags']) && is_array($_GET['tags']) && !empty($_GET['tags'])) {
// Sanitize each element of the tags array

View File

@@ -43,6 +43,9 @@ if (!$client_url) {
}
}
// Perms
enforceUserPermission('module_client');
// Tags Filter
if (isset($_GET['tags']) && is_array($_GET['tags']) && !empty($_GET['tags'])) {
// Sanitize each element of the tags array