Merge pull request #2444 from AlanCoding/2364_access_list_restriction

Filter access_list to users visible by requesting user
This commit is contained in:
Alan Rominger 2016-06-16 13:07:30 -04:00 committed by GitHub
commit cfc763af07

View File

@ -515,4 +515,4 @@ class ResourceAccessList(ListAPIView):
ancestors = set()
for r in roles:
ancestors.update(set(r.ancestors.all()))
return User.objects.filter(roles__in=list(ancestors)).distinct()
return self.request.user.get_queryset(User).filter(roles__in=list(ancestors)).distinct()