Allow admins and reviewers to view app resources

RESOLVED FIXED in 2013-05-23

Status

P2
normal
RESOLVED FIXED
5 years ago
5 years ago

People

(Reporter: robhudson, Assigned: ashort)

Tracking

({regression})

2013-05-23
regression
Points:
---
Dependency tree / graph

Details

(Reporter)

Description

5 years ago
If I visit a pending app as an admin or a reviewer the API currently returns a 403.
E.g. https://marketplace-dev.allizom.org/app/spirals (which is currently pending)

This is a regression of the current behavior where we allow admins and reviewers to view the page.

Similar to `AppOwnerAuthorization` used in `get_and_check_ownership` we could add something to check for admins or reviewers.
Keywords: regression
Priority: -- → P2
Blocks: 870020
(Reporter)

Updated

5 years ago
Assignee: nobody → robhudson.mozbugs
Target Milestone: --- → 2013-05-23
(Assignee)

Comment 1

5 years ago
https://github.com/mozilla/zamboni/commit/8380008
Status: NEW → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → FIXED
(Reporter)

Updated

5 years ago
Assignee: robhudson.mozbugs → ashort
You need to log in before you can comment on or make changes to this bug.