Commit 2d595c98 by 孙龙

权限

parent eaaaee50
Showing with 8 additions and 1 deletions
...@@ -460,12 +460,16 @@ class MessageController extends Controller ...@@ -460,12 +460,16 @@ class MessageController extends Controller
// 添加手动发送消息(会创建模板) // 添加手动发送消息(会创建模板)
private function sendmanualmessage(Request $request, $id, $viewid) private function sendmanualmessage(Request $request, $id, $viewid)
{ {
Csrf($request);
$perms_arr = ['manualmessage_send']; $perms_arr = ['manualmessage_send'];
$res_perm = $this->getUserPerms($request,$perms_arr); $res_perm = $this->getUserPerms($request,$perms_arr);
$manualmessage_send = $res_perm['manualmessage_send']; $manualmessage_send = $res_perm['manualmessage_send'];
if(!$manualmessage_send){
die("您没有权限查看");
}
//为所有历史消息的操作类型赋值 //为所有历史消息的操作类型赋值
$op_type = ''; $op_type = '';
if(empty($request['op_type'])) if(empty($request['op_type']))
...@@ -732,6 +736,9 @@ class MessageController extends Controller ...@@ -732,6 +736,9 @@ class MessageController extends Controller
{ {
$perms_arr = ['businessNotice']; $perms_arr = ['businessNotice'];
$res_perm = $this->getUserPerms($request,$perms_arr); $res_perm = $this->getUserPerms($request,$perms_arr);
if(!$res_perm || $res_perm["businessNotice"]){
die("您没有权限查看");
}
$data=[ $data=[
'have_perm'=>$res_perm, 'have_perm'=>$res_perm,
'id'=>$id, 'id'=>$id,
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or sign in to comment