From c0e0ca66eb36121fc919d45ba81766f41f8dc1d1 Mon Sep 17 00:00:00 2001 From: Ivlev Denis Date: Wed, 23 May 2018 17:12:59 +0300 Subject: [PATCH] Fix perms --- apps/course/views.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/course/views.py b/apps/course/views.py index be890e4c..08596935 100644 --- a/apps/course/views.py +++ b/apps/course/views.py @@ -167,7 +167,7 @@ class CourseEditView(TemplateView): self.object = Course.objects.create( author=request.user, ) - if request.user != self.object.author and request.user.role < User.AUTHOR_ROLE: + if (request.user != self.object.author and request.user.role < User.AUTHOR_ROLE) or request.user.role != User.ADMIN_ROLE: raise Http404 return super().get(request)