Skip to content

Commit a38fb5b

Browse files
committed
Disallow downloading unowned private data
1 parent c26ec53 commit a38fb5b

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

sasdata/fair_database/data/views.py

+2
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,8 @@ def download(request, data_id, version = None):
9292
# add session key later
9393
if not request.user.is_authenticated:
9494
return HttpResponseBadRequest("data is private, must log in")
95+
if not request.user == data.current_user:
96+
return HttpResponseBadRequest("data is private")
9597
# TODO add issues later
9698
try:
9799
file = open(data.file.path, 'rb')

0 commit comments

Comments
 (0)