From 221cbd15ab4e49dbc4634d1219c571e2f3d88b89 Mon Sep 17 00:00:00 2001 From: Raphael Michel Date: Sun, 5 Apr 2026 14:42:53 +0200 Subject: [PATCH] [SECURITY] API: Add missing event filter for check-ins --- src/pretix/api/views/checkin.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/pretix/api/views/checkin.py b/src/pretix/api/views/checkin.py index 4130229193..c6567a4d5c 100644 --- a/src/pretix/api/views/checkin.py +++ b/src/pretix/api/views/checkin.py @@ -1122,7 +1122,7 @@ class CheckinViewSet(viewsets.ReadOnlyModelViewSet): permission = 'event.orders:read' def get_queryset(self): - qs = Checkin.all.filter().select_related( + qs = Checkin.all.filter(list__event=self.request.event).select_related( "position", "device", )