SECURITY: Respect topic permissions when loading bookmark metadata

Co-authored-by: Martin Brennan <martin@discourse.org>
Co-authored-by: Sam Saffron <sam.saffron@gmail.com>
This commit is contained in:
David Taylor
2020-03-23 11:04:39 +00:00
parent 5ff505cea6
commit 5db41cd578
8 changed files with 151 additions and 31 deletions

View File

@@ -1401,7 +1401,7 @@ class UsersController < ApplicationController
respond_to do |format|
format.json do
bookmarks = BookmarkQuery.new(user, params).list_all
bookmarks = BookmarkQuery.new(user: user, guardian: guardian, params: params).list_all
if bookmarks.empty?
render json: {