Require correct permission for refunds in all cases

This commit is contained in:
Raphael Michel
2018-04-04 12:52:36 +02:00
parent ded15ecc3f
commit 7baabcef96
2 changed files with 2 additions and 2 deletions

View File

@@ -276,7 +276,7 @@ def oauth_disconnect(request, **kwargs):
}))
@event_permission_required('can_view_orders')
@event_permission_required('can_change_orders')
@require_POST
def refund(request, **kwargs):
with transaction.atomic():