FIX: can_permanently_delete should check for admin (#16348)

can_permanently_delete field in Post and TopicViewDetails serializers
cannot use Guardian's can_permanently_delete beause their use is
different. The field from the serializers is used to show the button
and the button is shown even if the post cannot be removed forever
because not enough time has passed since it was first deleted. The
guardian method is used by the controller to check that the post can
really be deleted.
This commit is contained in:
Bianca Nenciu
2022-04-01 04:03:39 +03:00
committed by GitHub
parent b023d88b09
commit 819038537c
3 changed files with 28 additions and 2 deletions

View File

@@ -173,7 +173,7 @@ class PostSerializer < BasicPostSerializer
end
def include_can_permanently_delete?
SiteSetting.can_permanently_delete && object.deleted_at
SiteSetting.can_permanently_delete && scope.is_admin? && object.deleted_at
end
def can_recover