diff --git a/application/Preorder/PreorderController.php b/application/Preorder/PreorderController.php index f5147c7f8..9caf363b4 100644 --- a/application/Preorder/PreorderController.php +++ b/application/Preorder/PreorderController.php @@ -1371,7 +1371,8 @@ class PreorderController extends mfBaseController { } private function deleteWorkorderApi() { - if(!$this->me->is("Admin")) { + if(!$this->me->is("Admin") && !$this->me->can("preorder")) { + $this->log->debug(__METHOD__.": no permission"); return false; }