From d32f0e0f56827c653902456b50ed71911a795a3c Mon Sep 17 00:00:00 2001 From: BonfaceKilz Date: Wed, 20 Oct 2021 14:11:16 +0300 Subject: decorators: Use the correct logic to check for edit_admins_access --- wqflask/wqflask/decorators.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'wqflask') diff --git a/wqflask/wqflask/decorators.py b/wqflask/wqflask/decorators.py index cd06aee7..843539ee 100644 --- a/wqflask/wqflask/decorators.py +++ b/wqflask/wqflask/decorators.py @@ -88,7 +88,7 @@ def edit_admins_access_required(f): except: response = {} if max([AdminRole(role) for role in response.get( - "data", ["not-admin"])]) >= AdminRole.EDIT_ADMINS: + "admin", ["not-admin"])]) < AdminRole.EDIT_ADMINS: return "You need to have edit-admins access", 401 return f(*args, **kwargs) return wrap -- cgit v1.2.3