From 01dd0645f49f115b50bcdb9785aaad4505446da0 Mon Sep 17 00:00:00 2001 From: shamoon <4887959+shamoon@users.noreply.github.com> Date: Fri, 5 Jun 2026 05:50:08 -0700 Subject: [PATCH] Require change perms for endpoint --- src/documents/views.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/documents/views.py b/src/documents/views.py index 511429129..4fc0b3f51 100644 --- a/src/documents/views.py +++ b/src/documents/views.py @@ -1400,7 +1400,7 @@ class DocumentViewSet( ) if request.user is not None and not has_perms_owner_aware( request.user, - "view_document", + "change_document", doc, ): return HttpResponseForbidden("Insufficient permissions") @@ -1460,7 +1460,7 @@ class DocumentViewSet( ) if request.user is not None and not has_perms_owner_aware( request.user, - "view_document", + "change_document", doc, ): return HttpResponseForbidden("Insufficient permissions")