Answer the question
In order to leave comments, you need to log in
How to properly grant access and check when editing?
Hello.
I have a marketplace site. Each user can create a store for himself. The one who created the store is the owner. The owner can grant access to other users, they become assistants.
Every store has merchandise. Information about these products can be edited.
When creating a product, there are several photos, I save the photos in a separate table, for each photo record I save its id. When editing a photo, you can delete it, when you click on the delete button, I will send the id of this photo via ajax. Instead of this id, you can send any other id, even someone else's product (by simply editing the value through F12). How to check that the owner of this store and assistants have access to this?
If you save the author's id for each photo, then only he can. How to check several users at once? And the owner and assistants
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question