From e99212a7bcadf3df8ce0438294409d83f5f93ff1 Mon Sep 17 00:00:00 2001 From: daitingting Date: Thu, 12 May 2022 05:52:16 +0000 Subject: [PATCH 1/2] * Check execution privilege in buildOperateMenu function. --- module/productplan/model.php | 37 ++++++++++++++++++------------------ 1 file changed, 19 insertions(+), 18 deletions(-) diff --git a/module/productplan/model.php b/module/productplan/model.php index 7ec779299b..1acd10ebed 100644 --- a/module/productplan/model.php +++ b/module/productplan/model.php @@ -1034,23 +1034,6 @@ class productplanModel extends model break; } - if($module == 'execution' && $action == 'create') - { - if($plan->parent < 0 || $plan->expired || in_array($plan->status, array('done', 'closed'))) return false; - - $product = $this->loadModel('product')->getById($plan->product); - $branchList = $this->loadModel('branch')->getList($plan->product, 0, 'all'); - - $branchStatusList = array(); - foreach($branchList as $productBranch) $branchStatusList[$productBranch->id] = $productBranch->status; - - if($product->type != 'normal') - { - $branchStatus = isset($branchStatusList[$plan->branch]) ? $branchStatusList[$plan->branch] : ''; - if($branchStatus == 'closed') return false; - } - } - return true; } @@ -1075,7 +1058,25 @@ class productplanModel extends model if($type == 'browse') { - if($this->isClickable($plan, 'create', 'execution')) + $canClickExecution = true; + if($plan->parent < 0 || $plan->expired || in_array($plan->status, array('done', 'closed')) || !common::hasPriv('execution', 'create', $plan)) $canClickExecution = false; + + if($canClickExecution) + { + $product = $this->loadModel('product')->getById($plan->product); + $branchList = $this->loadModel('branch')->getList($plan->product, 0, 'all'); + + $branchStatusList = array(); + foreach($branchList as $productBranch) $branchStatusList[$productBranch->id] = $productBranch->status; + + if($product->type != 'normal') + { + $branchStatus = isset($branchStatusList[$plan->branch]) ? $branchStatusList[$plan->branch] : ''; + if($branchStatus == 'closed') $canClickExecution = false; + } + } + + if(!$canClickExecution) { $executionLink = $this->config->systemMode == 'new' ? '#projects' : helper::createLink('execution', 'create', "projectID=0&executionID=0©ExecutionID=0&plan=$plan->id&confirm=no&productID=$plan->product"); if($this->config->systemMode == 'new') From da18989aa2025a0a4e2f6b76fda0eebf2fd79b1a Mon Sep 17 00:00:00 2001 From: daitingting Date: Thu, 12 May 2022 05:55:14 +0000 Subject: [PATCH 2/2] * Remove testin codes. --- module/productplan/model.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/module/productplan/model.php b/module/productplan/model.php index 1acd10ebed..ea4fac5627 100644 --- a/module/productplan/model.php +++ b/module/productplan/model.php @@ -1076,7 +1076,7 @@ class productplanModel extends model } } - if(!$canClickExecution) + if($canClickExecution) { $executionLink = $this->config->systemMode == 'new' ? '#projects' : helper::createLink('execution', 'create', "projectID=0&executionID=0©ExecutionID=0&plan=$plan->id&confirm=no&productID=$plan->product"); if($this->config->systemMode == 'new')