MDL-68084 blocks: check capability before getting content.
Some blocks (e.g. Calendar) load additional JS modules when returning content. We need to make sure they aren't asked to generate content unless the user can actually view the block, or the expected content required by the JS will not exist in the DOM and can cause exceptions.
This commit is contained in:
@@ -221,6 +221,11 @@ class block_base {
|
||||
public function get_content_for_output($output) {
|
||||
global $CFG;
|
||||
|
||||
// We can exit early if the current user doesn't have the capability to view the block.
|
||||
if (!has_capability('moodle/block:view', $this->context)) {
|
||||
return null;
|
||||
}
|
||||
|
||||
$bc = new block_contents($this->html_attributes());
|
||||
$bc->attributes['data-block'] = $this->name();
|
||||
$bc->blockinstanceid = $this->instance->id;
|
||||
|
||||
Reference in New Issue
Block a user