mirror of
https://github.com/itflow-org/itflow
synced 2026-03-01 11:24:52 +00:00
Tidying
- Move more things to new permissions system - Deduplicate assets post logic into model - Swap out some "SELECT *" queries when only a couple of rows are actually needed
This commit is contained in:
@@ -6,7 +6,7 @@
|
||||
|
||||
if (isset($_POST['add_service'])) {
|
||||
|
||||
validateTechRole();
|
||||
enforceUserPermission('module_support', 2);
|
||||
|
||||
$client_id = intval($_POST['client_id']);
|
||||
$service_name = sanitizeInput($_POST['name']);
|
||||
@@ -108,7 +108,7 @@ if (isset($_POST['add_service'])) {
|
||||
|
||||
if (isset($_POST['edit_service'])) {
|
||||
|
||||
validateTechRole();
|
||||
enforceUserPermission('module_support', 2);
|
||||
|
||||
$client_id = intval($_POST['client_id']);
|
||||
$service_id = intval($_POST['service_id']);
|
||||
@@ -212,7 +212,8 @@ if (isset($_POST['edit_service'])) {
|
||||
|
||||
if (isset($_GET['delete_service'])) {
|
||||
|
||||
validateAdminRole();
|
||||
enforceUserPermission('module_support', 3);
|
||||
validateCSRFToken($_GET['csrf_token']);
|
||||
|
||||
$service_id = intval($_GET['delete_service']);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user