Merge pull request #2444 from AlanCoding/2364_access_list_restriction

Filter access_list to users visible by requesting user
This commit is contained in:
Alan Rominger
2016-06-16 13:07:30 -04:00
committed by GitHub

View File

@@ -515,4 +515,4 @@ class ResourceAccessList(ListAPIView):
ancestors = set() ancestors = set()
for r in roles: for r in roles:
ancestors.update(set(r.ancestors.all())) ancestors.update(set(r.ancestors.all()))
return User.objects.filter(roles__in=list(ancestors)).distinct() return self.request.user.get_queryset(User).filter(roles__in=list(ancestors)).distinct()