Protect rrequests

This commit is contained in:
Sebastian Lohff 2017-03-27 02:53:19 +02:00
parent 337184baa6
commit eb722f950b
1 changed files with 3 additions and 1 deletions

View File

@ -4,6 +4,7 @@ from django.urls import reverse
from django.views.generic import FormView from django.views.generic import FormView
from django.contrib.auth.mixins import LoginRequiredMixin from django.contrib.auth.mixins import LoginRequiredMixin
from django.contrib.auth.decorators import login_required from django.contrib.auth.decorators import login_required
from django.db.models import Q
from django.utils import timezone from django.utils import timezone
@ -53,7 +54,8 @@ class RrequestCreate(LoginRequiredMixin, FormView):
@login_required @login_required
def rrequestDetail(request, pk): def rrequestDetail(request, pk):
reqObj = get_object_or_404(Request, pk=pk) mnts = request.user.maintainer_set.all()
reqObj = get_object_or_404(Request.objects.filter(Q(provider__in=mnts) | Q(applicant__in=mnts)), pk=pk)
mnts = request.user.maintainer_set.all() mnts = request.user.maintainer_set.all()
formClass = None formClass = None