Code of Conduct
Is there an existing issue for this?
GLPI Version
11.0.6
Plugin version
1.15.7
Bug description
Hi
I have an AccessDeniedHttpException when trying to add credit to a ticket, even with Super-Admin profile.
Bug is there since 1.15.5.
I think the problem is in ticket.form.php, line 62 (for 1.15.7) as the variable passed to Session::haveAccessToEntity should be the entity id of GLPI and not the voucher id.
if (!Session::haveAccessToEntity($_REQUEST['plugin_credit_entities_id'])) {
throw new AccessDeniedHttpException();
}
$_REQUEST['plugin_credit_entities_id'] contains plugin_credit_entities table "id" field and not "entities_id" field
If I remove this test, everything works.
The entity test in ticket.php is checking the correct field.
Best regards,
Relevant log output
Page URL
No response
Steps To reproduce
- Try to add credit to a ticket
Your GLPI setup information
No response
Anything else?
No response
Code of Conduct
Is there an existing issue for this?
GLPI Version
11.0.6
Plugin version
1.15.7
Bug description
Hi
I have an AccessDeniedHttpException when trying to add credit to a ticket, even with Super-Admin profile.
Bug is there since 1.15.5.
I think the problem is in ticket.form.php, line 62 (for 1.15.7) as the variable passed to Session::haveAccessToEntity should be the entity id of GLPI and not the voucher id.
$_REQUEST['plugin_credit_entities_id'] contains plugin_credit_entities table "id" field and not "entities_id" field
If I remove this test, everything works.
The entity test in ticket.php is checking the correct field.
Best regards,
Relevant log output
Page URL
No response
Steps To reproduce
Your GLPI setup information
No response
Anything else?
No response