From: yomguy Date: Fri, 10 Jun 2011 16:35:37 +0000 (+0200) Subject: avoid item access when item.collection.public_acccess is none X-Git-Tag: 1.1~113 X-Git-Url: https://git.parisson.com/?a=commitdiff_plain;h=26d9066588ee774a0763900a1611408cc67b8301;p=telemeta.git avoid item access when item.collection.public_acccess is none --- diff --git a/telemeta/web/base.py b/telemeta/web/base.py index 2c4219a3..0452d24b 100644 --- a/telemeta/web/base.py +++ b/telemeta/web/base.py @@ -256,7 +256,7 @@ class WebView(object): else: item = MediaItem.objects.get(public_id=public_id) - if item.public_access == 'none' and not request.user.is_staff: + if (item.public_access == 'none' or item.collection.public_access == 'none') and not request.user.is_staff: return HttpResponseRedirect('not_allowed/') # Get TimeSide processors