Resolve Unprotected Absence Reasons queries
Resolves the first part of #41 (closed)
Edited by permcu
Merge request reports
Activity
changed milestone to /AlekSIS%"[NLnet #6 (closed)] Process issues found in testing and security audit"
assigned to @hansegucker
I secured fetching absence reasons and made it possible for all authenticated users again. But I am unsure why editing absence reasons as student works. The AbsenceBatchPatchMutation has the permission kolego.edit_absence_rule set. I think it could be a issue with PermissionBatchPatchMixin and set @yuha on the case.
mentioned in commit 3da7ea22
Please register or sign in to reply