FIX: Change is_staff to is_admin to match other places where guardian.allowed_category_ids is used

https://meta.discourse.org/t/security-permissions-and-messages-displayed-on-group-url/22169/17
This commit is contained in:
cpradio 2014-11-16 20:31:16 -05:00
parent 22fa46b1f2
commit bf7be0c130
1 changed files with 1 additions and 1 deletions

View File

@ -42,7 +42,7 @@ class Group < ActiveRecord::Base
.where('topics.archetype <> ?', Archetype.private_message)
.where(post_type: Post.types[:regular])
unless guardian.is_staff?
unless guardian.is_admin?
allowed_ids = guardian.allowed_category_ids
if allowed_ids.length > 0
result = result.where('topics.category_id IS NULL or topics.category_id IN (?)', allowed_ids)