Skip to content

Commit

Permalink
Bugfix: Authorized User only gets findings through API of which he is…
Browse files Browse the repository at this point in the history
… the reporter of #2992 (#2998)

* Bugfix: Authorized User only gets findings through API of which he is the reporter of #2992

* Update views.py

Co-authored-by: Volker Weyandt <Volker.Weyandt@t-systems.com>
  • Loading branch information
Yuuichi89 and tsys-vowe committed Oct 13, 2020
1 parent 1313495 commit 14e5581
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions dojo/api_v2/views.py
Original file line number Diff line number Diff line change
Expand Up @@ -257,7 +257,7 @@ def perform_update(self, serializer):
def get_queryset(self):
if not self.request.user.is_staff:
findings = Finding.objects.filter(
reporter_id__in=[self.request.user])
test__engagement__product__authorized_users__in=[self.request.user])
else:
findings = Finding.objects.all()
return findings.prefetch_related('test',
Expand Down Expand Up @@ -712,7 +712,7 @@ class StubFindingsViewSet(mixins.ListModelMixin,
def get_queryset(self):
if not self.request.user.is_staff:
return Finding.objects.filter(
reporter_id__in=[self.request.user])
test__engagement__product__authorized_users__in=[self.request.user])
else:
return Finding.objects.all()

Expand Down

0 comments on commit 14e5581

Please sign in to comment.