With this followup, a user without order_manage permission won't be able
to cick on a basket and a user without group_manage permission won't be
able to click on a basketgroup
Signed-off-by: Mark Tompsett <mtompset@hotmail.com>
Signed-off-by: Katrin Fischer <Katrin.Fischer.83@web.de>
Signed-off-by: Galen Charlton <gmc@esilibrary.com>
[% lateorder.subtotal %]
</td>
<td>
- <a href="basket.pl?basketno=[% lateorder.basketno %]" title="basket">[% lateorder.basketname %] ([% lateorder.basketno %])</a>
+ [% IF ( CAN_user_acquisition_order_manage ) %]
+ <a href="basket.pl?basketno=[% lateorder.basketno %]" title="basket">[% lateorder.basketname %] ([% lateorder.basketno %])</a>
+ [% ELSE %]
+ [% lateorder.basketname %] ([% lateorder.basketno %])
+ [% END %]
</td>
<td>
- <a href="basketgroup.pl?op=add&booksellerid=[% lateorder.supplierid %]&basketgroupid=[% lateorder.basketgroupid %]" title="basketgroup">[% lateorder.basketgroupname %] ([% lateorder.basketgroupid %])</a>
+ [% IF ( CAN_user_acquisition_group_manage ) %]
+ <a href="basketgroup.pl?op=add&booksellerid=[% lateorder.supplierid %]&basketgroupid=[% lateorder.basketgroupid %]" title="basketgroup">[% lateorder.basketgroupname %] ([% lateorder.basketgroupid %])</a>
+ [% ELSE %]
+ [% lateorder.basketgroupname %] ([% lateorder.basketgroupid %])</a>
+ [% END %]
</td>
<td>[% lateorder.branch %]
</td>