mirror of
https://github.com/optim-enterprises-bv/Mailu.git
synced 2025-10-30 17:47:55 +00:00
Fix permission management when editing/deleting fetches
This commit is contained in:
@@ -46,6 +46,6 @@ def get_fetch(fetch_id):
|
|||||||
if not fetch:
|
if not fetch:
|
||||||
flask.abort(404)
|
flask.abort(404)
|
||||||
if not fetch.user.domain in flask_login.current_user.get_managed_domains():
|
if not fetch.user.domain in flask_login.current_user.get_managed_domains():
|
||||||
if not fetch.user == flask_login.current_user:
|
if not fetch.user.email == flask_login.current_user.email:
|
||||||
flask.abort(403)
|
flask.abort(403)
|
||||||
return fetch
|
return fetch
|
||||||
|
|||||||
Reference in New Issue
Block a user