return $res;
}
// normally allowed, but we have more restrictions...
- switch($res->tablename()) {
+ switch($obj->tablename()) {
case 'core_enum':
-
-
+ if (empty($req['etype']) {
+ return false;
+ }
+ switch ($req['etype']) {
+
+ if ($perm == 'S') {
+ return true;
+ }
+
+
+ if (!$au) {
+ return false;
+ }
+
+ if ($au->company()->comptype == 'OWNER') {
+ return true;
+ }
+
+ // not a member of the company..
+ // not allowed in..
+ return false;