Skip to content
Snippets Groups Projects
Commit 7040932c authored by root's avatar root
Browse files

Fixes : Broken access control in migration module issue is fixed

parent d10c41f7
No related branches found
No related tags found
No related merge requests found
...@@ -23,8 +23,8 @@ class Migration_Extract_Action extends Vtiger_Action_Controller { ...@@ -23,8 +23,8 @@ class Migration_Extract_Action extends Vtiger_Action_Controller {
$user->column_fields['user_name'] = $userName; $user->column_fields['user_name'] = $userName;
$userid = $user->retrieve_user_id($userName); $userid = $user->retrieve_user_id($userName);
$userRecordModel = Users_Privileges_Model::getInstanceById($userid, 'Users'); $userRecordModel = Users_Privileges_Model::getInstanceById($userid, 'Users');
if ($user->doLogin($password)) { if($userRecordModel->isAdminUser()) {
if($userRecordModel->isAdminUser()) { if ($user->doLogin($password)) {
$zip = new ZipArchive(); $zip = new ZipArchive();
$fileName = 'vtiger8.zip'; $fileName = 'vtiger8.zip';
if ($zip->open($fileName)) { if ($zip->open($fileName)) {
...@@ -47,11 +47,11 @@ class Migration_Extract_Action extends Vtiger_Action_Controller { ...@@ -47,11 +47,11 @@ class Migration_Extract_Action extends Vtiger_Action_Controller {
header('Location: migrate/index.php?error='.$errorMessage); header('Location: migrate/index.php?error='.$errorMessage);
} }
} else { } else {
$errorMessage = 'PERMISSION DENIED! ONLY ADMIN USERS CAN ACCESS'; $errorMessage = 'INVALID CREDENTIALS';
header('Location: migrate/index.php?error='.$errorMessage); header('Location: migrate/index.php?error='.$errorMessage);
} }
} else { } else {
$errorMessage = 'INVALID CREDENTIALS'; $errorMessage = 'PERMISSION DENIED! ONLY ADMIN USERS CAN ACCESS';
header('Location: migrate/index.php?error='.$errorMessage); header('Location: migrate/index.php?error='.$errorMessage);
} }
} }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment