From d1637b4baa0b68335c387c27845e09b1af816dbe Mon Sep 17 00:00:00 2001 From: Robert Sesek Date: Wed, 12 Oct 2005 03:58:31 +0000 Subject: [PATCH] r546: Additional permission checking --- showhistory.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/showhistory.php b/showhistory.php index 05ef0f4..0b1c985 100644 --- a/showhistory.php +++ b/showhistory.php @@ -27,7 +27,7 @@ if (!$bug) $message->error($lang->getlex('error_invalid_id')); } -if ($bug['hidden'] AND !can_perform('canviewhidden', $bug['productid'])) +if (($bug['hidden'] AND !can_perform('canviewhidden', $bug['productid'])) OR !can_perform('canviewbugs', $bug['productid'])) { $message->error_permission(); } -- 2.22.5