🐛 Fix request authorisation

Signed-off-by: Luke Tainton <luke@tainton.uk>
This commit is contained in:
2020-08-09 17:15:33 +01:00
parent 671e1826d0
commit 9e25c836bb

View File

@@ -127,13 +127,17 @@ function get_updates($db, $request) {
}
function get_subscribers($db, $request) {
$subs = array();
$users_stmt = "SELECT user_uuid FROM ticket_subscribers WHERE ticket_uuid=:uuid";
$users_sql = $db->prepare($users_stmt);
$users_sql->bindParam(':uuid', $request['uuid']);
$users_sql->execute();
$users_sql->setFetchMode(PDO::FETCH_ASSOC);
$users_result = $users_sql->fetchAll();
return $users_result;
foreach ($users_result as $u) {
array_push($subs, $u['user_uuid']);
}
return $subs;
}
function isAuthorised($user, $authorised_users, $request) {