MDL-83180 reportbuilder: correct access check for viewing schedules.

This commit is contained in:
Paul Holden
2024-10-02 16:50:08 +08:00
committed by Jun Pataleta
parent 90d7307872
commit bb6a65da42
2 changed files with 8 additions and 1 deletions
@@ -91,7 +91,10 @@ class report_schedules extends system_report {
* @return bool
*/
protected function can_view(): bool {
return permission::can_view_reports_list();
$reportid = $this->get_parameter('reportid', 0, PARAM_INT);
$report = report::get_record(['id' => $reportid], MUST_EXIST);
return permission::can_edit_report($report);
}
/**
+4
View File
@@ -71,6 +71,8 @@ abstract class system_report extends base {
* This is necessary to implement independently of the page that would typically embed the report because
* subsequent pages are requested via AJAX requests, and access should be validated each time
*
* Report parameters should also be considered when implementing this method
*
* @return bool
*/
abstract protected function can_view(): bool;
@@ -201,6 +203,8 @@ abstract class system_report extends base {
/**
* Return specific report parameter
*
* Capability/permission checks relating to parameters retrieved here should also be considered in your {@see can_view} method
*
* @param string $param
* @param mixed $default
* @param string $type