Ignore:
Timestamp:
25 Nov 2008, 20:19:24 (16 years ago)
Author:
Henrik Bettermann
Message:

more beds for futminna

moree security for course_result_list

Location:
WAeUP_SRP/trunk/skins/waeup_student
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • WAeUP_SRP/trunk/skins/waeup_student/course_result_list.py

    r3781 r3786  
    1414request = context.REQUEST
    1515setheader = request.RESPONSE.setHeader
     16
     17mtool = context.portal_membership
     18if mtool.isAnonymousUser():
     19    return request.RESPONSE.redirect("%s/srp_anonymous_view" % context.portal_url())
     20member = mtool.getAuthenticatedMember()
     21member_id = str(member)
     22students_folder = context.portal_url.getPortalObject().campus.students
     23
     24if not students_folder.isSectionOfficer():
     25    logger.info('%s tried to access %s' % (member_id,requested_id))
     26    return 'Not allowed'
     27
     28
     29
    1630cr = context.course_results
    1731scat = context.students_catalog
  • WAeUP_SRP/trunk/skins/waeup_student/lecturer_course_edit.py

    r3752 r3786  
    7777        data['key'] = object['key']
    7878        context.course_results.modifyRecord(**data)
    79         logger.info('%s edited course result data %s' % (student_id, course_id))
     79        logger.info('%s edited course result %s of %s' % (member_id,course_id,student_id))
    8080        psm = 'psm_content_changed'
    8181        break
Note: See TracChangeset for help on using the changeset viewer.