diff --git a/main/mySpace/myStudents.php b/main/mySpace/myStudents.php index f796e2e7ab..224e2a190b 100644 --- a/main/mySpace/myStudents.php +++ b/main/mySpace/myStudents.php @@ -217,7 +217,7 @@ if (!empty ($_GET['student'])) { // infos about user $info_user = UserManager :: get_user_info_by_id($student_id); - if ($_user['status'] == DRH && $info_user['hr_dept_id'] != $_user['user_id']) { + if($_user['status']==DRH && $a_infosUser['hr_dept_id']!=$_user['user_id'] && !api_is_platform_admin()) { api_not_allowed(); } diff --git a/main/tracking/courseLog.php b/main/tracking/courseLog.php index c8ac695a9c..9004f74ef6 100644 --- a/main/tracking/courseLog.php +++ b/main/tracking/courseLog.php @@ -35,7 +35,7 @@ if (isset($_GET['from']) && $_GET['from'] == 'myspace') { } // access restrictions -$is_allowedToTrack = $is_courseAdmin || $is_platformAdmin || $is_courseCoach || $is_sessionAdmin; +$is_allowedToTrack = api_is_course_admin() || api_is_platform_admin() || api_is_course_coach() || $is_sessionAdmin; if (!$is_allowedToTrack) { Display :: display_header(null);