Changeset 8126 for trunk/plugins/admin_multi_view
- Timestamp:
- Dec 14, 2010, 2:47:24 PM (13 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/plugins/admin_multi_view/controller.php
r8012 r8126 31 31 if ( isset($_GET['view_as']) ) 32 32 { 33 if ( is_adviser() and $user['id']!=$_GET['view_as'] and $conf['guest_id']!=$_GET['view_as'])34 die('security error');35 33 if ($user['id']===$_GET['view_as']) 36 34 pwg_unset_session_var( 'multiview_as' ); … … 112 110 $query = ' 113 111 SELECT '.$conf['user_fields']['id'].' AS id,'.$conf['user_fields']['username'].' AS username 114 FROM '.USERS_TABLE; 115 if (is_adviser()) 116 { 117 $query .=' 118 WHERE '.$conf['user_fields']['id']. ' IN ('.$user['id'].','.$conf['guest_id'].') 119 '; 120 } 121 $query .=' 112 FROM '.USERS_TABLE.' 122 113 ORDER BY CONVERT('.$conf['user_fields']['username'].',CHAR) 123 114 ;';
Note: See TracChangeset
for help on using the changeset viewer.