restrict queryset for access_list to visable users

This commit is contained in:
AlanCoding 2016-06-15 10:52:25 -04:00
parent 69c994bd16
commit 54fa11cf25

View File

@ -515,4 +515,4 @@ class ResourceAccessList(ListAPIView):
ancestors = set()
for r in roles:
ancestors.update(set(r.ancestors.all()))
return User.objects.filter(roles__in=list(ancestors)).distinct()
return self.request.user.get_queryset(User).filter(roles__in=list(ancestors)).distinct()