From 1fe399a1d1dfa44018d8b99e038853f751c2537d Mon Sep 17 00:00:00 2001 From: Diatrex Date: Thu, 31 Oct 2019 12:02:52 +0300 Subject: [PATCH] #125 can't edit the ad unless you are logged in with the ad profile --- .../advs-module/src/Http/Controller/advsController.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/addons/default/visiosoft/advs-module/src/Http/Controller/advsController.php b/addons/default/visiosoft/advs-module/src/Http/Controller/advsController.php index 5d7475e8c..8cf4d6ddd 100644 --- a/addons/default/visiosoft/advs-module/src/Http/Controller/advsController.php +++ b/addons/default/visiosoft/advs-module/src/Http/Controller/advsController.php @@ -674,7 +674,7 @@ class AdvsController extends PublicController $adv = $advRepository->getAdvArray($id); - if ($adv['created_by_id'] != Auth::id()) { + if ($adv['created_by_id'] != Auth::id() && !Auth::user()->hasRole('admin')) { abort(403); } $cats_d = array();