FIX: SS_Report canView should check permissions

... checks for ADMIN / CMS_ACCESS_ReportAdmin (from ReportAdmin)

fixes #13
This commit is contained in:
Christopher Darling 2015-12-15 16:32:23 +00:00
parent 7b245c6df9
commit 5d0f833a39

View File

@ -308,8 +308,15 @@ class SS_Report extends ViewableData {
if(!$member && $member !== FALSE) {
$member = Member::currentUser();
}
return true;
$extended = $this->extendedCan('canView', $member);
if($extended !== null) return $extended;
if($member && Permission::checkMember($member, array('CMS_ACCESS_LeftAndMain', 'CMS_ACCESS_ReportAdmin'))) {
return true;
}
return false;
}