Skip to content

Commit

Permalink
add control on back_signalement_visite_deleterapport #2645
Browse files Browse the repository at this point in the history
  • Loading branch information
numew committed Jun 11, 2024
1 parent 7dc41bc commit 82d237c
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions src/Controller/Back/SignalementVisitesController.php
Original file line number Diff line number Diff line change
Expand Up @@ -341,6 +341,7 @@ public function deleteRapportVisiteFromSignalement(
EntityManagerInterface $entityManager,
UploadHandlerService $uploadHandlerService,
): Response {
$this->denyAccessUnlessGranted('INTERVENTION_EDIT_VISITE', $intervention);
if (!$this->isCsrfTokenValid('delete_rapport', $request->get('_token')) || $intervention->getSignalement()->getId() !== $signalement->getId() || $intervention->getFiles()->isEmpty()) {
return $this->redirectToRoute('back_signalement_view', ['uuid' => $signalement->getUuid()]);
}
Expand Down

0 comments on commit 82d237c

Please sign in to comment.