Closed (fixed)
Project:
Storm
Version:
6.x-1.9
Component:
Code
Priority:
Critical
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
14 Dec 2008 at 21:40 UTC
Updated:
16 Jan 2009 at 09:00 UTC
As of 6.x-1.9, I see no way to allow a client to view invoiceitems of their organization without allowing them to view the invoiceitems of other organizations, if they guessed the urls. We need a "view of user organization" permission for invoiceitems, which functions exactly the same way as the same named permissions for invoices, etc.
Comments
Comment #1
Roberto Gerola commentedI've added a permission check based on invoice privileges for children invoice items.
Committed on cvs for dev version for testing.
Let me know.
Thanks, Roberto
Comment #2
Roberto Gerola commented