-
- Downloads
fix: remove superfluous retrieve/update actions for APIUserViewSet
The retrieve and update actions can be removed because the get_queryset method already ensures that the user has only access to their own user object (or all user objects in case of superusers). Sending 401 responses for unauthorized requests may also be considered leaky, because it exposes that these objects exist instead of returning a 404 that simply states that no object with that primary key can be found.
parent
addf232f
No related branches found
No related tags found
This commit is part of merge request !21. Comments created here will be created in the context of that merge request.
Please register or sign in to comment