From 12f10ef3a99030260f2c8254449fb76c10fdf7be Mon Sep 17 00:00:00 2001 From: Roly Rudy Gutierrez Pinto Date: Tue, 9 Nov 2021 11:08:01 -0400 Subject: [PATCH] PMCORE-3512 Any user can claim a case --- workflow/engine/src/ProcessMaker/BusinessModel/Cases.php | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/workflow/engine/src/ProcessMaker/BusinessModel/Cases.php b/workflow/engine/src/ProcessMaker/BusinessModel/Cases.php index e126ae178..a160091da 100644 --- a/workflow/engine/src/ProcessMaker/BusinessModel/Cases.php +++ b/workflow/engine/src/ProcessMaker/BusinessModel/Cases.php @@ -1134,6 +1134,13 @@ class Cases if (empty($delegation['USR_UID'])) { $case = new ClassesCases(); $case->loadCase($appUid); + + //Review if the user can be claim the case + if (!$case->isSelfService($userUid, $delegation['TAS_UID'], $appUid)) { + $message = preg_replace("##i", "", G::LoadTranslation("ID_NO_PERMISSION_NO_PARTICIPATED")); + throw new Exception($message); + } + $case->setCatchUser($appUid, $index, $userUid); } else { throw new Exception(G::LoadTranslation("ID_CASE_USER_INVALID_CLAIM_CASE", [$userUid]));