DataObjects/Core_person_settings.php wip_edward_T5791_Search_Criteria_on_Orders_Columns
authorEdward <edward@roojs.com>
Tue, 2 Apr 2019 04:05:04 +0000 (12:05 +0800)
committerEdward <edward@roojs.com>
Tue, 2 Apr 2019 04:05:04 +0000 (12:05 +0800)
DataObjects/Core_person_settings.php

index 1005ea5..0dd1ac7 100644 (file)
@@ -29,4 +29,14 @@ class Pman_Core_DataObjects_Core_person_settings extends DB_DataObject
         
     }
     
+    function beforeUpdate($old, $q, $roo)
+    {
+        if(
+                !$roo->authUser ||
+                (!empty($this->person_id) && $this->person_id != $roo->authUser->id)
+        ) {
+            $roo->jerr('Access Dennied');
+        }
+    }
+    
  }