From eb10d8350bdfcfa223196a6429acbb1dfff8101f Mon Sep 17 00:00:00 2001 From: Raphael Michel Date: Sun, 5 Apr 2026 14:42:53 +0200 Subject: [PATCH] [SECURITY] API: Add missing event filter for check-ins --- src/pretix/api/views/checkin.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/pretix/api/views/checkin.py b/src/pretix/api/views/checkin.py index 7a7d50e97a..dd56100ac8 100644 --- a/src/pretix/api/views/checkin.py +++ b/src/pretix/api/views/checkin.py @@ -1117,7 +1117,7 @@ class CheckinViewSet(viewsets.ReadOnlyModelViewSet): permission = 'can_view_orders' def get_queryset(self): - qs = Checkin.all.filter().select_related( + qs = Checkin.all.filter(list__event=self.request.event).select_related( "position", "device", )