Fixing CredentialList post access check

This commit is contained in:
Wayne Witzel III 2016-04-26 14:36:22 -04:00
parent 077db7931f
commit 2b589228d3

View File

@ -1225,7 +1225,7 @@ class CredentialList(ListCreateAPIView):
organization = Organization.objects.get(pk=request.data['organization'])
obj = organization
if self.request.user not in obj.admin_role:
if not self.request.user.can_access(type(obj), 'admin', obj, request.data):
raise PermissionDenied()
ret = super(CredentialList, self).post(request, *args, **kwargs)