Stopgap fix for lack fo permissions check on organistions

This commit is contained in:
Magnus Hagander
2018-12-22 16:07:28 +01:00
parent d36ea4a985
commit 0d1832dc0d

View File

@ -1,4 +1,4 @@
from django.shortcuts import render
from django.shortcuts import render, get_object_or_404
from django.http import HttpResponse, Http404, HttpResponseRedirect
from django.http import HttpResponseNotModified
from django.template import TemplateDoesNotExist, loader
@ -126,6 +126,8 @@ def fallback(request, url):
# Edit-forms for core objects
@login_required
def organisationform(request, itemid):
get_object_or_404(Organisation, pk=itemid, managers=request.user)
return simple_form(Organisation, itemid, request, OrganisationForm,
redirect='/account/edit/organisations/')