MDL-45760 make sure to check permission before setting header

This commit is contained in:
Marina Glancy
2014-07-07 15:06:57 +01:00
committed by Dan Poltawski
parent a2bf5412a7
commit 8f7d596058
+7 -5
View File
@@ -15,6 +15,10 @@ $userid = optional_param('user', 0, PARAM_INT);
$filtertype = optional_param('filtertype', '', PARAM_ALPHA);
$filterselect = optional_param('filterselect', 0, PARAM_INT);
if (empty($CFG->enablenotes)) {
print_error('notesdisabled', 'notes');
}
$url = new moodle_url('/notes/index.php');
if ($courseid != SITEID) {
$url->param('course', $courseid);
@@ -61,11 +65,6 @@ if ($userid) {
/// require login to access notes
require_login($course);
add_to_log($courseid, 'notes', 'view', 'index.php?course='.$courseid.'&user='.$userid, 'view notes');
if (empty($CFG->enablenotes)) {
print_error('notesdisabled', 'notes');
}
/// output HTML
if ($course->id == SITEID) {
@@ -73,8 +72,11 @@ if ($course->id == SITEID) {
} else {
$coursecontext = context_course::instance($course->id); // Course context
}
require_capability('moodle/notes:view', $coursecontext);
$systemcontext = context_system::instance(); // SYSTEM context
add_to_log($courseid, 'notes', 'view', 'index.php?course='.$courseid.'&user='.$userid, 'view notes');
$strnotes = get_string('notes', 'notes');
if ($userid) {
$PAGE->set_context(context_user::instance($user->id));