diff --git a/Controller.php b/Controller.php index fa059c1..64990f1 100644 --- a/Controller.php +++ b/Controller.php @@ -195,8 +195,10 @@ class Controller extends ModuleAbstract implements WebInterface { $view = new View($this->app, $request, $response); + $accountId = $request->getHeader()->getAccount(); + if (!$this->app->accountManager->get($accountId)->hasPermission( - PermissionType::CREATE, $this->app->orgId, $this->app->appName, self::MODULE_ID, PermissionState::BOARD, $board->getId()) + PermissionType::CREATE, $this->app->orgId, $this->app->appName, self::MODULE_ID, PermissionState::BOARD) ) { $view->setTemplate('/Web/Backend/Error/403_inline'); $response->getHeader()->setStatusCode(RequestStatusCode::R_403);