Skip to content
Snippets Groups Projects

Fix security issue

Merged Jonathan Weth requested to merge yuha/AlekSIS-Core:master into master
2 files
+ 4
3
Compare changes
  • Side-by-side
  • Inline
Files
2
@@ -246,9 +246,9 @@ class Query(graphene.ObjectType):
def resolve_pdf_by_id(root, info, id, **kwargs): # noqa
pdf_file = PDFFile.objects.get(pk=id)
if has_person(info.context) and info.context.user.person != pdf_file.person:
return None
return pdf_file
if has_person(info.context) and info.context.user.person == pdf_file.person:
return pdf_file
return None
def resolve_search_snippets(root, info, query, limit=-1, **kwargs):
indexed_models = UnifiedIndex().get_indexed_models()
Loading