Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Dashboard Shows Bank Data for Unauthorized User - SOLVED
05-03-2018, 03:50 AM, (This post was last modified: 05-03-2018, 03:57 AM by VortecCPI.)
#1
Dashboard Shows Bank Data for Unauthorized User - SOLVED
Dashboard.php

Shows a Bank Account and related data fro an account not authorized to a User.

All other Bank Account scripts seem to comply and work fine with ACL.
Fixed by changing SQL from this:
PHP Code:
    $Sql "SELECT bankaccounts.accountcode,
                    bankaccounts.bankaccountcode,
                    chartmaster.accountname,
                    bankaccountname
            FROM bankaccounts INNER JOIN chartmaster
            ON bankaccounts.accountcode = chartmaster.accountcode"


To this:
PHP Code:
    $Sql "SELECT bankaccounts.accountcode,
                    bankaccounts.bankaccountcode,
                    chartmaster.accountname,
                    bankaccountname
            FROM bankaccounts
            INNER JOIN chartmaster
            ON bankaccounts.accountcode = chartmaster.accountcode
            INNER JOIN bankaccountusers
            ON bankaccounts.accountcode=bankaccountusers.accountcode
            AND userid='" 
$_SESSION['UserID'] . "'"
https://www.linkedin.com/in/eclipsepaulbecker
Reply


Messages In This Thread
Dashboard Shows Bank Data for Unauthorized User - SOLVED - by VortecCPI - 05-03-2018, 03:50 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)