diff --git a/modules/CustomView/actions/Delete.php b/modules/CustomView/actions/Delete.php index 963cf6baf8f36af2811968d8fd358878039ba879..f6dc2c99e7a78efac67369559737ad98c5417840 100644 --- a/modules/CustomView/actions/Delete.php +++ b/modules/CustomView/actions/Delete.php @@ -25,7 +25,7 @@ class CustomView_Delete_Action extends Vtiger_Action_Controller { $moduleModel = $customViewModel->getModule(); $customViewOwner = $customViewModel->getOwnerId(); $currentUser = Users_Record_Model::getCurrentUserModel(); - if ((!$currentUser->isAdminUser()) || ($customViewOwner != $currentUser->getId())) { + if ((!$currentUser->isAdminUser()) && ($customViewOwner != $currentUser->getId())) { throw new AppException(vtranslate('LBL_PERMISSION_DENIED')); } $customViewModel->delete();