visuddhinanda 2 лет назад
Родитель
Сommit
db538b17d4
1 измененных файлов с 9 добавлено и 1 удалено
  1. 9 1
      app/Http/Controllers/ArticleController.php

+ 9 - 1
app/Http/Controllers/ArticleController.php

@@ -254,7 +254,15 @@ class ArticleController extends Controller
 
         $canManage = ArticleController::userCanManage($user_uid,$request->get('studio'));
         if(!$canManage){
-            return $this->error(__('auth.failed'),[],403);
+            //判断是否有文集权限
+            if($request->has('anthologyId')){
+                $currPower = ShareApi::getResPower($user_uid,$request->get('anthologyId'));
+                if($currPower <= 10){
+                    return $this->error(__('auth.failed'),[],403);
+                }
+            }else{
+                return $this->error(__('auth.failed'),[],403);
+            }
         }
         //权限判断结束