diff --git a/application/Espo/Controllers/User.php b/application/Espo/Controllers/User.php index ffc8a54461..d543f5013f 100644 --- a/application/Espo/Controllers/User.php +++ b/application/Espo/Controllers/User.php @@ -18,7 +18,7 @@ * * You should have received a copy of the GNU General Public License * along with EspoCRM. If not, see http://www.gnu.org/licenses/. - ************************************************************************/ + ************************************************************************/ namespace Espo\Controllers; @@ -35,30 +35,33 @@ class User extends \Espo\Core\Controllers\Record if (empty($userId)) { throw new Error(); } - + if (!$this->getUser()->isAdmin() && $this->getUser()->id != $userId) { throw new Forbidden(); } - + $user = $this->getEntityManager()->getEntity('User', $userId); if (empty($user)) { throw new NotFound(); } - + $acl = new \Espo\Core\Acl($user, $this->getConfig(), $this->getContainer()->get('fileManager'), $this->getMetadata()); - + return $acl->toArray(); } - - public function actionChangeOwnPassword($params, $data) + + public function actionChangeOwnPassword($params, $data, $request) { + if (!$request->isPost()) { + throw new BadRequest(); + } return $this->getService('User')->changePassword($this->getUser()->id, $data['password']); } public function actionChangePasswordByRequest($params, $data, $request) { if (!$request->isPost()) { - throw new Forbidden(); + throw new BadRequest(); } if (empty($data['requestId']) || empty($data['password'])) { throw new BadRequest(); diff --git a/frontend/client/src/views/notifications/list.js b/frontend/client/src/views/notifications/list.js new file mode 100644 index 0000000000..ed95cbafce --- /dev/null +++ b/frontend/client/src/views/notifications/list.js @@ -0,0 +1,44 @@ +/************************************************************************ + * This file is part of EspoCRM. + * + * EspoCRM - Open Source CRM application. + * Copyright (C) 2014-2015 Yuri Kuznetsov, Taras Machyshyn, Oleksiy Avramenko + * Website: http://www.espocrm.com + * + * EspoCRM is free software: you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * EspoCRM is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with EspoCRM. If not, see http://www.gnu.org/licenses/. + ************************************************************************/ + +Espo.define('Views.Notifications.List', 'Views.Record.ListExpanded', function (Dep) { + + return Dep.extend({ + + actionViewRecord: function (data) { + var id = data.id; + var scope = data.scope; + + this.notify('Loading...'); + this.createView('quickDetail', 'Modals.Detail', { + scope: scope, + id: id + }, function (view) { + view.once('after:render', function () { + Espo.Ui.notify(false); + }); + view.render(); + }.bind(this)); + } + + }); + +}); diff --git a/frontend/client/src/views/notifications/panel.js b/frontend/client/src/views/notifications/panel.js index 51e7881bf1..d5f5671456 100644 --- a/frontend/client/src/views/notifications/panel.js +++ b/frontend/client/src/views/notifications/panel.js @@ -47,7 +47,7 @@ Espo.define('Views.Notifications.Panel', 'View', function (Dep) { afterRender: function () { this.listenToOnce(this.collection, 'sync', function () { - this.createView('list', 'Record.ListExpanded', { + this.createView('list', 'Notifications.List', { el: this.options.el + ' .list-container', collection: this.collection, showCount: false, @@ -74,7 +74,7 @@ Espo.define('Views.Notifications.Panel', 'View', function (Dep) { }); }.bind(this)); this.collection.fetch(); - }, + } });