From 0e1105fb2b1c418c88b6397d973920d9ec4bb691 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=81lex=20Hermida?= Date: Wed, 28 Nov 2018 08:01:38 +0100 Subject: [PATCH] Check permissions on webnotifications list --- taiga/projects/notifications/api.py | 3 +++ 1 file changed, 3 insertions(+) diff --git a/taiga/projects/notifications/api.py b/taiga/projects/notifications/api.py index a3363b26..6ed963d4 100644 --- a/taiga/projects/notifications/api.py +++ b/taiga/projects/notifications/api.py @@ -65,6 +65,9 @@ class WebNotificationsViewSet(GenericViewSet): request.user.pk == obj.user_id def list(self, request): + if self.request.user.is_anonymous(): + return response.Ok({}) + queryset = models.WebNotification.objects\ .filter(user=self.request.user)