Never return database values for read-only fields.

This commit is contained in:
Chris Church 2016-11-15 00:59:10 -05:00
parent e22b0f75b8
commit 89c629e796

View File

@ -68,7 +68,7 @@ class SettingSingletonDetail(RetrieveUpdateDestroyAPIView):
if self.category_slug not in category_slugs:
raise PermissionDenied()
registered_settings = settings_registry.get_registered_settings(category_slug=self.category_slug)
registered_settings = settings_registry.get_registered_settings(category_slug=self.category_slug, read_only=False)
if self.category_slug == 'user':
return Setting.objects.filter(key__in=registered_settings, user=self.request.user)
else: