MDL-59776 core_calendar: prevent deletion of module events

This commit is contained in:
Simey Lameze
2017-09-07 11:01:09 +02:00
committed by David Monllao
parent 2da5effd17
commit 233d271a91
2 changed files with 7 additions and 5 deletions
+4 -3
View File
@@ -58,9 +58,11 @@ if (!$course) {
$PAGE->set_context(context_system::instance()); //TODO: wrong
}
$title = get_string('deleteevent', 'calendar');
// Check the user has the required capabilities to edit an event
if (!calendar_edit_event_allowed($event)) {
print_error('nopermissions');
if (!calendar_edit_event_allowed($event) || !empty($event->modulename)) {
print_error('nopermissions', 'error', $PAGE->url, $title);
}
// Count the repeats, do we need to consider the possibility of deleting repeats
@@ -88,7 +90,6 @@ if ($confirm) {
}
// Prepare the page to show the confirmation form
$title = get_string('deleteevent', 'calendar');
$strcalendar = get_string('calendar', 'calendar');
$PAGE->navbar->add($strcalendar, $viewcalendarurl);
+3 -2
View File
@@ -86,8 +86,9 @@ class core_calendar_external extends external_api {
$eventobj = calendar_event::load($event['eventid']);
// Let's check if the user is allowed to delete an event.
if (!calendar_edit_event_allowed($eventobj)) {
throw new moodle_exception("nopermissions");
if (!empty($eventobj->modulename) || !calendar_edit_event_allowed($eventobj)) {
throw new moodle_exception("nopermissions", 'error', '',
get_string('deleteevent', 'calendar'));
}
// Time to do the magic.
$eventobj->delete($event['repeat']);