From 8d7149bc2ffdae94bfa8391b63eb0cbb8a7c2907 Mon Sep 17 00:00:00 2001 From: Civiware Solutions Date: Sun, 12 Aug 2018 00:10:06 +0530 Subject: [PATCH] Added permission for page --- CRM/Grant/Page/AnnualBudgets.php | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/CRM/Grant/Page/AnnualBudgets.php b/CRM/Grant/Page/AnnualBudgets.php index b341480..4d14390 100644 --- a/CRM/Grant/Page/AnnualBudgets.php +++ b/CRM/Grant/Page/AnnualBudgets.php @@ -26,6 +26,15 @@ class CRM_Grant_Page_AnnualBudgets extends CRM_Core_Page_Basic { * Browse all Grant Budget. */ public function browse() { + + //check permission + if (!(CRM_Core_Permission::check('administer CiviCRM') + || ( CRM_Core_Permission::check('access CiviGrant') + && CRM_Core_Permission::check('edit grants') + ) + )) { + return CRM_Utils_System::permissionDenied(); + } $fiscalYear = CRM_Utils_Request::retrieve('fiscalYears', 'Positive'); if (empty($fiscalYear)) { $fiscalYear = date('Y');