Delete perms: must be staff and in group
This commit is contained in:
parent
21e0c6d656
commit
d1b1fe1433
1 changed files with 1 additions and 1 deletions
|
@ -17,7 +17,7 @@ def del_list(request, list_id: int, list_slug: str) -> HttpResponse:
|
|||
|
||||
# Ensure user has permission to delete list. Get the group this list belongs to,
|
||||
# and check whether current user is a member of that group AND a staffer.
|
||||
if task_list.group not in request.user.groups.all() and not request.user.is_staff:
|
||||
if not (task_list.group in request.user.groups.all() and request.user.is_staff):
|
||||
raise PermissionDenied
|
||||
|
||||
if request.method == "POST":
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue