Improve user checking for mailing reports
authorDave Jenkins <davej+git@circle-interactive.co.uk>
Fri, 26 May 2017 17:34:51 +0000 (18:34 +0100)
committerDave Jenkins <davej+git@circle-interactive.co.uk>
Fri, 26 May 2017 17:34:51 +0000 (18:34 +0100)
CRM/Mailing/Page/Event.php

index e923ea8771a68c52d02aecf0b18b4811d6ba1f33..beb7ffb16d1848a3131115d5ff65caf8eb37e33d 100644 (file)
@@ -63,6 +63,9 @@ class CRM_Mailing_Page_Event extends CRM_Core_Page {
 
     $mailing_id = CRM_Utils_Request::retrieve('mid', 'Positive', $this);
 
+    // check that the user has permission to access mailing id
+    CRM_Mailing_BAO_Mailing::checkPermission($mailing_id);
+
     //assign backurl
     $context = CRM_Utils_Request::retrieve('context', 'String', $this);