]> git.mjollnir.org Git - moodle.git/commitdiff
Fixed some bung security logic
authormoodler <moodler>
Sat, 25 Mar 2006 16:19:06 +0000 (16:19 +0000)
committermoodler <moodler>
Sat, 25 Mar 2006 16:19:06 +0000 (16:19 +0000)
mod/data/add.php

index e0eb5f8d07ae585c50496c407a5677d2db2e8999..b1fffed296ab447fb9f8e80e91e55d31dc70a14c 100755 (executable)
@@ -68,9 +68,9 @@
         error (get_string('noaccess','data'));
     }
 
-    if ($rid){    //editting a record, do you have access to edit this?
-        if (!isteacher($course->id) or !data_isowner($rid) or !confirm_sesskey()){
-            error (get_string('noaccess','data'));
+    if ($rid) {    // So do you have access?
+        if (!(isteacher($course->id) or data_isowner($rid)) or !confirm_sesskey() ) {
+            error(get_string('noaccess','data'));
         }
     }