浏览代码

FIX: Add right to manage chart of accounts for non-admin

aspangaro 9 年之前
父节点
当前提交
df91a95b9b
共有 1 个文件被更改,包括 3 次插入1 次删除
  1. 3 1
      htdocs/accountancy/admin/account.php

+ 3 - 1
htdocs/accountancy/admin/account.php

@@ -43,7 +43,9 @@ $search_pcgtype = GETPOST("search_pcgtype");
 $search_pcgsubtype = GETPOST("search_pcgsubtype");
 
 // Security check
-if (! $user->admin)
+if ($user->societe_id > 0)
+	accessforbidden();
+if (! $user->rights->accounting->chartofaccount)
 	accessforbidden();
 
 $sortfield = GETPOST("sortfield", 'alpha');