From ac17af6834afd64e4b163a1f2b6e30052c2beea7 Mon Sep 17 00:00:00 2001 From: FusionPBX Date: Sun, 24 Dec 2017 01:14:12 -0700 Subject: [PATCH] Update cmd.php --- app/number_translations/cmd.php | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/app/number_translations/cmd.php b/app/number_translations/cmd.php index ead9257cc4..e959a71a3e 100644 --- a/app/number_translations/cmd.php +++ b/app/number_translations/cmd.php @@ -24,13 +24,19 @@ Matthew Vale */ -include "root.php"; -require_once "resources/require.php"; -require_once "resources/check_auth.php"; -if (!if_group("superadmin")) { - echo "access denied"; - exit; -} +//includes + require_once "root.php"; + require_once "resources/require.php"; + require_once "resources/check_auth.php"; + +//check permissions + if (permission_exists('number_translation_add') || permission_exists('number_translation_edit')) { + //access granted + } + else { + echo "access denied"; + exit; + } //set the variables $cmd = check_str($_GET['cmd']); @@ -39,7 +45,6 @@ if (!if_group("superadmin")) { //create the event socket connection $fp = event_socket_create($_SESSION['event_socket_ip_address'], $_SESSION['event_socket_port'], $_SESSION['event_socket_password']); if ($fp) { - //reloadxml if ($cmd == "api reloadxml") { messages::add(rtrim(event_socket_request($fp, $cmd)), 'alert'); @@ -65,4 +70,4 @@ if (!if_group("superadmin")) { header("Location: number_translations.php"); } -?> \ No newline at end of file +?>