Version 4.7.23
This commit is contained in:
1 parent
7124a02564
commit
25ddeb65d6
1791 files changed
+76990
-44452
No files matched your search
@@ -11,6 +11,9 @@
|
||||
namespace IPS\Content\Api;
|
||||
|
||||
/* To prevent PHP errors (extending class does not exist) revealing path */
|
||||
|
||||
use OutOfRangeException;
|
||||
|
||||
if ( !\defined( '\IPS\SUITE_UNIQUE_KEY' ) )
|
||||
{
|
||||
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
|
||||
@@ -201,9 +204,16 @@ class _ItemController extends \IPS\Api\Controller
|
||||
$class = $this->class;
|
||||
|
||||
$item = $class::load( $id );
|
||||
if ( $this->member and !$item->can( 'read', $this->member ) )
|
||||
if( $this->member )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
if ( method_exists($item, 'canView') and !$item->canView( $this->member ) )
|
||||
{
|
||||
throw new OutOfRangeException;
|
||||
}
|
||||
else if ( !$item->can( 'read', $this->member ) )
|
||||
{
|
||||
throw new OutOfRangeException;
|
||||
}
|
||||
}
|
||||
|
||||
return new \IPS\Api\Response( 200, $item->apiOutput( $this->member ) );
|
||||
@@ -536,9 +546,16 @@ class _ItemController extends \IPS\Api\Controller
|
||||
/* Init */
|
||||
$itemClass = $this->class;
|
||||
$item = $itemClass::load( $id );
|
||||
if ( $this->member and !$item->can( 'read', $this->member ) )
|
||||
if( $this->member )
|
||||
{
|
||||
throw new \OutOfRangeException;
|
||||
if ( method_exists($item, 'canView') and !$item->canView( $this->member ) )
|
||||
{
|
||||
throw new OutOfRangeException;
|
||||
}
|
||||
else if ( !$item->can( 'read', $this->member ) )
|
||||
{
|
||||
throw new OutOfRangeException;
|
||||
}
|
||||
}
|
||||
$itemIdColumn = $itemClass::$databaseColumnId;
|
||||
$where [] = array( $commentClass::$databasePrefix . $commentClass::$databaseColumnMap['item'] . '=?', $item->$itemIdColumn );
|
||||
|
||||
Reference in new issue
Block a user