Skip to content

Commit 0c5102e

Browse files
fix permission check
1 parent 008456a commit 0c5102e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

dojo/api_v2/serializers.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1616,7 +1616,7 @@ def validate_findings_have_same_engagement(finding_objects: list[Finding]):
16161616
findings = data.get("accepted_findings", [])
16171617
findings_ids = [x.id for x in findings]
16181618
finding_objects = Finding.objects.filter(id__in=findings_ids)
1619-
authed_findings = get_authorized_findings(Permissions.Finding_Edit).filter(id__in=findings_ids)
1619+
authed_findings = get_authorized_findings(Permissions.Risk_Acceptance).filter(id__in=findings_ids)
16201620
if len(findings) != len(authed_findings):
16211621
msg = "You are not permitted to add one or more selected findings to this risk acceptance"
16221622
raise PermissionDenied(msg)

0 commit comments

Comments
 (0)