diff --git a/controllers/OrderController.php b/controllers/OrderController.php index dd7491e..6d75810 100755 --- a/controllers/OrderController.php +++ b/controllers/OrderController.php @@ -4,6 +4,7 @@ use artweb\artbox\components\SmsSender; use artweb\artbox\ecommerce\models\OrderSearch; + use common\models\User; use phpDocumentor\Reflection\Types\Null_; use Yii; use yii\helpers\ArrayHelper; @@ -289,9 +290,13 @@ } $model = $this->findModel($id); - + + /** + * @var User $user + */ + $user = \Yii::$app->user->identity; if ($model->isBlocked() && $model->edit_id !== \Yii::$app->user->id) { - if (!\Yii::$app->user->identity->isAdmin()) { + if (!$user->isAdmin()) { throw new ForbiddenHttpException(); } } -- libgit2 0.21.4