diff --git a/src/main/java/au/com/royalpay/payment/manage/permission/manager/ManagerUserInterceptor.java b/src/main/java/au/com/royalpay/payment/manage/permission/manager/ManagerUserInterceptor.java index 124ffe67c..644449dcd 100644 --- a/src/main/java/au/com/royalpay/payment/manage/permission/manager/ManagerUserInterceptor.java +++ b/src/main/java/au/com/royalpay/payment/manage/permission/manager/ManagerUserInterceptor.java @@ -104,13 +104,13 @@ public class ManagerUserInterceptor extends HandlerInterceptorAdapter implements } } -// JSONObject func = permissionPartnerManager.getPartnerFuncById(funcId); -// if(func!=null && StringUtils.isNotEmpty(func.getString("module_id"))){ -// JSONArray arr = loginUser.getJSONArray("available_module_ids"); -// if (arr == null || !arr.contains(func.getString("module_id"))) { -// throw new ForbiddenException("error.permission.nopermission"); -// } -// } + JSONObject func = permissionPartnerManager.getPartnerFuncById(funcId); + if(func!=null && StringUtils.isNotEmpty(func.getString("module_id"))){ + JSONArray arr = loginUser.getJSONArray("available_module_ids"); + if (arr == null || !arr.contains(func.getString("module_id"))) { + throw new ForbiddenException("error.permission.nopermission"); + } + } request.setAttribute(CommonConsts.PARTNER_STATUS, loginUser); } diff --git a/src/main/ui/index.html b/src/main/ui/index.html index fffcf5385..60ad4e993 100644 --- a/src/main/ui/index.html +++ b/src/main/ui/index.html @@ -926,17 +926,27 @@ margin-bottom: 10%;"/> <!––>Sale --> -