diff options
| author | Étienne Loks <etienne.loks@iggdrasil.net> | 2016-04-19 23:26:46 +0200 |
|---|---|---|
| committer | Étienne Loks <etienne.loks@iggdrasil.net> | 2016-04-19 23:26:46 +0200 |
| commit | 28cd3982a7df9bc8e49a9cc8bf1f005c45681952 (patch) | |
| tree | 852a056fa32199ec85aa3780c543ce108997a1ae | |
| parent | 57f8d74874a3c7b572689a8af9e0edfeaa4d1cc7 (diff) | |
| download | Ishtar-28cd3982a7df9bc8e49a9cc8bf1f005c45681952.tar.bz2 Ishtar-28cd3982a7df9bc8e49a9cc8bf1f005c45681952.zip | |
Fix permission checking in order to get own item
| -rw-r--r-- | ishtar_common/views.py | 3 |
1 files changed, 2 insertions, 1 deletions
diff --git a/ishtar_common/views.py b/ishtar_common/views.py index 296d56648..f4a8d02e2 100644 --- a/ishtar_common/views.py +++ b/ishtar_common/views.py @@ -349,7 +349,8 @@ def get_item(model, func_name, default_name, extra_request_keys=[], # if not specific any perm is relevant (read right) if specific_perms and perm not in specific_perms: continue - if request.user.has_perm(model._meta.app_label + '.' + perm) \ + cperm = model._meta.app_label + '.' + perm + if cperm in request.user.get_all_permissions() \ or (request.user.is_authenticated() and request.user.ishtaruser.has_right( perm, session=request.session)): |
