From fca335020a0589afccc0c8f404f657b5ffcf37b5 Mon Sep 17 00:00:00 2001 From: Raphael Michel Date: Sun, 5 Apr 2026 14:42:53 +0200 Subject: [PATCH] [SECURITY] API: Add missing event filter for check-ins --- src/pretix/api/views/checkin.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/pretix/api/views/checkin.py b/src/pretix/api/views/checkin.py index 7fb054e24..d907e93ac 100644 --- a/src/pretix/api/views/checkin.py +++ b/src/pretix/api/views/checkin.py @@ -1121,7 +1121,7 @@ class CheckinViewSet(viewsets.ReadOnlyModelViewSet): permission = 'can_view_orders' def get_queryset(self): - qs = Checkin.all.filter().select_related( + qs = Checkin.all.filter(list__event=self.request.event).select_related( "position", "device", )