forked from CGM_Public/pretix_original
Require correct permission for refunds in all cases
This commit is contained in:
@@ -177,7 +177,7 @@ def webhook(request, *args, **kwargs):
|
|||||||
return HttpResponse(status=200)
|
return HttpResponse(status=200)
|
||||||
|
|
||||||
|
|
||||||
@event_permission_required('can_view_orders')
|
@event_permission_required('can_change_orders')
|
||||||
@require_POST
|
@require_POST
|
||||||
def refund(request, **kwargs):
|
def refund(request, **kwargs):
|
||||||
with transaction.atomic():
|
with transaction.atomic():
|
||||||
|
|||||||
@@ -276,7 +276,7 @@ def oauth_disconnect(request, **kwargs):
|
|||||||
}))
|
}))
|
||||||
|
|
||||||
|
|
||||||
@event_permission_required('can_view_orders')
|
@event_permission_required('can_change_orders')
|
||||||
@require_POST
|
@require_POST
|
||||||
def refund(request, **kwargs):
|
def refund(request, **kwargs):
|
||||||
with transaction.atomic():
|
with transaction.atomic():
|
||||||
|
|||||||
Reference in New Issue
Block a user