Protect message reply functions with 'create' permission.

This commit is contained in:
Lance Edgar 2016-02-10 22:17:49 -06:00
parent 46923d40da
commit ad9cd8be8e
2 changed files with 8 additions and 4 deletions

View file

@ -333,11 +333,13 @@ class MessagesView(MasterView):
# reply
config.add_route('messages.reply', '/messages/{uuid}/reply')
config.add_view(cls, attr='reply', route_name='messages.reply')
config.add_view(cls, attr='reply', route_name='messages.reply',
permission='messages.create')
# reply-all
config.add_route('messages.reply_all', '/messages/{uuid}/reply-all')
config.add_view(cls, attr='reply_all', route_name='messages.reply_all')
config.add_view(cls, attr='reply_all', route_name='messages.reply_all',
permission='messages.create')
# move (single)
config.add_route('messages.move', '/messages/{uuid}/move')