forked from 0x2620/pandora
rendered items should only be available to users that can edit them, fixes #1197
This commit is contained in:
parent
8466c054f2
commit
9491d68227
2 changed files with 15 additions and 4 deletions
|
|
@ -194,10 +194,15 @@ class Item(models.Model):
|
|||
level = 'guest'
|
||||
else:
|
||||
level = user.get_profile().get_level()
|
||||
editable = self.editable(user)
|
||||
if editable:
|
||||
return True
|
||||
if not self.rendered and settings.CONFIG.get('itemRequiresVideo'):
|
||||
return False
|
||||
allowed_level = settings.CONFIG['capabilities']['canSeeItem'][level]
|
||||
if self.level <= allowed_level:
|
||||
return True
|
||||
return self.editable(user)
|
||||
return False
|
||||
|
||||
def editable(self, user):
|
||||
if user.is_anonymous():
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue