Koha/catalogue
Jonathan Druart ea263a2284 Bug 14449: Add authentication check on retrieving item info when receiving
The script catalogue/getitem-ajax.pl is called by acqui/orderreceive.pl
when item is receipt.
There is not auth check done, this means anybody can retrieve item info.

Test plan:
With the acquisition => order_receive permission, try to receive an
item.
It should work.

Signed-off-by: Chris Cormack <chrisc@catalyst.net.nz>

Very easy to test.

Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>
Signed-off-by: Tomas Cohen Arazi <tomascohen@unc.edu.ar>
2015-07-20 10:10:59 -03:00
..
detail.pl
export.pl
getitem-ajax.pl Bug 14449: Add authentication check on retrieving item info when receiving 2015-07-20 10:10:59 -03:00
image.pl
imageviewer.pl
ISBDdetail.pl
issuehistory.pl
itemsearch.pl Bug 13950: Sort Item search home library list by branch name 2015-07-08 14:44:57 -03:00
labeledMARCdetail.pl
MARCdetail.pl
moredetail.pl
search-history.pl
search.pl Bug 14431: FIX encoding issues in search (staff client) 2015-07-07 14:51:39 -03:00
showmarc.pl
updateitem.pl