From 51eaa5f8be9f79142208d909d1725acc6393df4c Mon Sep 17 00:00:00 2001 From: rasstislav Date: Sun, 25 Sep 2016 14:17:02 +0200 Subject: [PATCH] added check if canView --- code/controller/WidgetContentControllerExtension.php | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/code/controller/WidgetContentControllerExtension.php b/code/controller/WidgetContentControllerExtension.php index f28947a..3fdfb5e 100644 --- a/code/controller/WidgetContentControllerExtension.php +++ b/code/controller/WidgetContentControllerExtension.php @@ -63,6 +63,10 @@ class WidgetContentControllerExtension extends Extension user_error('No widget found', E_USER_ERROR); } + if (!$widget->canView()) { + return Security::permissionFailure(); + } + return $widget->getController(); } }