We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 09e91b3 commit f60f3d5Copy full SHA for f60f3d5
1 file changed
users/permissions.py
@@ -7,8 +7,9 @@ class IsAchievementOwnerOrReadOnly(BasePermission):
7
"""
8
9
def has_permission(self, request, view) -> bool:
10
- # todo check if user is achievement owner
11
- if request.method in SAFE_METHODS or (request.user and request.user.id):
+ if request.method in SAFE_METHODS or (
+ request.user and request.user.id == request.data.get("user")
12
+ ):
13
return True
14
return False
15
0 commit comments