CredentialAccess fix to ensure appropriate access to what we're adding a credential to

This commit is contained in:
Akita Noek 2016-05-02 15:43:12 -04:00
parent c7f2568c10
commit 826874d61c

View File

@ -595,6 +595,8 @@ class CredentialAccess(BaseAccess):
@check_superuser
def can_change(self, obj, data):
if not self.can_add(data):
return False
return self.user in obj.owner_role
def can_delete(self, obj):