diff --git a/CRM/Grant/Page/AnnualBudgets.php b/CRM/Grant/Page/AnnualBudgets.php index b341480..4d14390 100644 --- a/CRM/Grant/Page/AnnualBudgets.php +++ b/CRM/Grant/Page/AnnualBudgets.php @@ -26,6 +26,15 @@ class CRM_Grant_Page_AnnualBudgets extends CRM_Core_Page_Basic { * Browse all Grant Budget. */ public function browse() { + + //check permission + if (!(CRM_Core_Permission::check('administer CiviCRM') + || ( CRM_Core_Permission::check('access CiviGrant') + && CRM_Core_Permission::check('edit grants') + ) + )) { + return CRM_Utils_System::permissionDenied(); + } $fiscalYear = CRM_Utils_Request::retrieve('fiscalYears', 'Positive'); if (empty($fiscalYear)) { $fiscalYear = date('Y');