Skip to content

Commit 4802177

Browse files
committed
Enforce object permissions check when rendering forms in browseable API
1 parent 5ed3f59 commit 4802177

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rest_framework/renderers.py

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -349,6 +349,7 @@ def show_form_for_method(self, view, method, request, obj):
349349

350350
try:
351351
view.check_permissions(request)
352+
view.check_object_permissions(request, obj)
352353
except exceptions.APIException:
353354
return False # Doesn't have permissions
354355
return True

0 commit comments

Comments
 (0)