diff --git a/controllers/project_controller.php b/controllers/project_controller.php index 08c2bcc..7dd930f 100644 --- a/controllers/project_controller.php +++ b/controllers/project_controller.php @@ -129,6 +129,10 @@ // Dans la cas de modif if (isset($_GET['id'])){ $arrProject = $objProjectModel->findOne($_GET['id']); + if($_SESSION['user']['user_id'] != $arrProject['project_user_id']){ + header("Location:index.php?ctrl=error&action=error_403"); + exit; + } $objProject->hydrate($arrProject); // BDD $this->_arrData['arrImages'] = $objProjectModel->getImagesByProjectId($objProject->getId()); }