From 4523d7c6e59b42e35b833d5ee41843f36d1f42e8 Mon Sep 17 00:00:00 2001 From: Julio Montoya Date: Fri, 19 Apr 2013 13:31:14 +0200 Subject: [PATCH] Removing $is_allowed_in_course already checked in api_protect_course --- main/blog/blog_admin.php | 2 +- main/document/create_audio.php | 6 +----- main/document/create_document.php | 16 ++++++---------- main/document/create_draw.php | 4 ---- main/document/create_paint.php | 6 +----- main/document/document.php | 1 + main/document/download.php | 18 +++++++++--------- main/document/record_audio.php | 4 ---- main/document/record_audio_wami.php | 4 ---- main/document/show_content.php | 8 -------- main/document/showinframes.php | 7 ------- main/document/showinframesmin.php | 8 -------- main/document/webcam_clip.php | 4 ---- main/group/group.php | 3 --- main/group/group_overview.php | 4 ---- main/metadata/phpdig/search.php | 6 +++--- 16 files changed, 22 insertions(+), 79 deletions(-) diff --git a/main/blog/blog_admin.php b/main/blog/blog_admin.php index 89459f0a32..0c23dfabdf 100644 --- a/main/blog/blog_admin.php +++ b/main/blog/blog_admin.php @@ -23,7 +23,7 @@ $blog_table_attachment = Database::get_course_table(TABLE_BLOGS_ATTACHMENT); api_protect_course_script(true); // ONLY USERS REGISTERED IN THE COURSE -if((!$is_allowed_in_course || !$is_courseMember) && !api_is_allowed_to_edit()) { +if((!$is_courseMember) && !api_is_allowed_to_edit()) { api_not_allowed(true);//print headers/footers } diff --git a/main/document/create_audio.php b/main/document/create_audio.php index a81ed12ba3..f1ec63254e 100644 --- a/main/document/create_audio.php +++ b/main/document/create_audio.php @@ -27,6 +27,7 @@ $nameTools = get_lang('CreateAudio'); api_protect_course_script(); api_block_anonymous_users(); + if (api_get_setting('enabled_text2audio') == 'false') { api_not_allowed(true); } @@ -92,11 +93,6 @@ $interbreadcrumb[] = array( "name" => get_lang('Documents') ); -if (!$is_allowed_in_course) { - api_not_allowed(true); -} - - if (!($is_allowed_to_edit || $_SESSION['group_member_with_upload_rights'] || is_my_shared_folder( api_get_user_id(), Security::remove_XSS($dir), diff --git a/main/document/create_document.php b/main/document/create_document.php index e1467fd70d..8addea4b9c 100644 --- a/main/document/create_document.php +++ b/main/document/create_document.php @@ -15,11 +15,12 @@ $language_file = array('document', 'gradebook'); require_once '../inc/global.inc.php'; +api_protect_course_script(); + $_SESSION['whereami'] = 'document/create'; $this_section = SECTION_COURSES; -$htmlHeadXtra[] = ' -