From 801a8a6c4a3a9df1d20643542eb881cee8ce414a Mon Sep 17 00:00:00 2001 From: Cayo Puigdefabregas Date: Thu, 6 Aug 2020 16:51:49 +0200 Subject: [PATCH] add filter as user owner --- ereuse_devicehub/resources/documents/documents.py | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/ereuse_devicehub/resources/documents/documents.py b/ereuse_devicehub/resources/documents/documents.py index 7373f91a..084fd6e4 100644 --- a/ereuse_devicehub/resources/documents/documents.py +++ b/ereuse_devicehub/resources/documents/documents.py @@ -10,7 +10,7 @@ import flask import flask_weasyprint import teal.marshmallow from boltons import urlutils -from flask import make_response +from flask import make_response, g from teal.cache import cache from teal.resource import Resource @@ -130,7 +130,7 @@ class DevicesDocumentView(DeviceView): class StockDocumentView(DeviceView): # @cache(datetime.timedelta(minutes=1)) def find(self, args: dict): - query = self.query(args) + query = (x for x in self.query(args) if x.owner_id==g.user.id) return self.generate_post_csv(query) def generate_post_csv(self, query): @@ -182,6 +182,7 @@ class DocumentDef(Resource): auth=app.auth) stock_view = StockDocumentView.as_view('stockDocumentView', definition=self) + stock_view = app.auth.requires_auth(stock_view) if self.AUTH: devices_view = app.auth.requires_auth(devices_view)