From 5647f5314054bdebc7894eceffc79ec92695525b Mon Sep 17 00:00:00 2001 From: Jens Langhammer Date: Fri, 25 Dec 2020 22:42:53 +0100 Subject: [PATCH] core: fix anonymous user being included in User API # Conflicts: # authentik/admin/views/applications.py --- authentik/core/api/users.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/authentik/core/api/users.py b/authentik/core/api/users.py index c2446d8c3..69e47c0e5 100644 --- a/authentik/core/api/users.py +++ b/authentik/core/api/users.py @@ -1,5 +1,6 @@ """User API Views""" from drf_yasg2.utils import swagger_auto_schema +from guardian.utils import get_anonymous_user from rest_framework.decorators import action from rest_framework.request import Request from rest_framework.response import Response @@ -33,7 +34,7 @@ class UserSerializer(ModelSerializer): class UserViewSet(ModelViewSet): """User Viewset""" - queryset = User.objects.all() + queryset = User.objects.all().exclude(pk=get_anonymous_user().pk) serializer_class = UserSerializer def get_queryset(self):