$contactID = CRM_Utils_Type::escape($_GET['cid'], 'Integer');
$context = CRM_Utils_Type::escape($_GET['context'], 'String');
+ if (!CRM_Contact_BAO_Contact_Permission::allow($contactID)) {
+ return CRM_Utils_System::permissionDenied();
+ }
+
$sortMapper = array(
0 => 'relation',
1 => 'sort_name',
<item>
<path>civicrm/ajax/contactrelationships</path>
<page_callback>CRM_Contact_Page_AJAX::getContactRelationships</page_callback>
- <access_arguments>view all contacts;view my contact</access_arguments>
+ <access_arguments>access CiviCRM;view my contact</access_arguments>
</item>
</menu>