MDL-59776 core_calendar: prevent deletion of module events
This commit is contained in:
committed by
David Monllao
parent
2da5effd17
commit
233d271a91
+4
-3
@@ -58,9 +58,11 @@ if (!$course) {
|
||||
$PAGE->set_context(context_system::instance()); //TODO: wrong
|
||||
}
|
||||
|
||||
$title = get_string('deleteevent', 'calendar');
|
||||
|
||||
// Check the user has the required capabilities to edit an event
|
||||
if (!calendar_edit_event_allowed($event)) {
|
||||
print_error('nopermissions');
|
||||
if (!calendar_edit_event_allowed($event) || !empty($event->modulename)) {
|
||||
print_error('nopermissions', 'error', $PAGE->url, $title);
|
||||
}
|
||||
|
||||
// Count the repeats, do we need to consider the possibility of deleting repeats
|
||||
@@ -88,7 +90,6 @@ if ($confirm) {
|
||||
}
|
||||
|
||||
// Prepare the page to show the confirmation form
|
||||
$title = get_string('deleteevent', 'calendar');
|
||||
$strcalendar = get_string('calendar', 'calendar');
|
||||
|
||||
$PAGE->navbar->add($strcalendar, $viewcalendarurl);
|
||||
|
||||
@@ -86,8 +86,9 @@ class core_calendar_external extends external_api {
|
||||
$eventobj = calendar_event::load($event['eventid']);
|
||||
|
||||
// Let's check if the user is allowed to delete an event.
|
||||
if (!calendar_edit_event_allowed($eventobj)) {
|
||||
throw new moodle_exception("nopermissions");
|
||||
if (!empty($eventobj->modulename) || !calendar_edit_event_allowed($eventobj)) {
|
||||
throw new moodle_exception("nopermissions", 'error', '',
|
||||
get_string('deleteevent', 'calendar'));
|
||||
}
|
||||
// Time to do the magic.
|
||||
$eventobj->delete($event['repeat']);
|
||||
|
||||
Reference in New Issue
Block a user