diff --git a/program/views.py b/program/views.py index 83fca0586b747a9a975cbb315537c54bead8fdd1..9ea46433dca8de73e62249d311ec70164a40834b 100644 --- a/program/views.py +++ b/program/views.py @@ -724,7 +724,7 @@ class APINoteViewSet( user = self.request.user - if self.request.method in permissions.SAFE_METHODS or user.is_superuser: + if self.request.method in permissions.SAFE_METHODS or user.has_perm("update_note"): return Note.objects.all() else: return Note.objects.filter(timeslot__schedule__show__owners=user)