diff --git a/modules/CustomView/actions/DeleteAjax.php b/modules/CustomView/actions/DeleteAjax.php index d7932d621932b324e86e63cad37f0fc3861fc757..d6c9ffaab8569773b60db2fcc76ad4c4add1066d 100644 --- a/modules/CustomView/actions/DeleteAjax.php +++ b/modules/CustomView/actions/DeleteAjax.php @@ -32,7 +32,7 @@ class CustomView_DeleteAjax_Action extends Vtiger_Action_Controller { $customViewModel = CustomView_Record_Model::getInstanceById($request->get('record')); $customViewOwner = $customViewModel->getOwnerId(); $currentUser = Users_Record_Model::getCurrentUserModel(); - if ((!$currentUser->isAdminUser()) || ($customViewOwner != $currentUser->getId())) { + if ((!$currentUser->isAdminUser()) && ($customViewOwner != $currentUser->getId())) { throw new AppException(vtranslate('LBL_PERMISSION_DENIED')); } $customViewModel->delete();