mirror of
https://github.com/HabitRPG/habitica.git
synced 2025-12-17 22:57:21 +01:00
fix(challenge): don't pierce privacy on GET/:id
This commit is contained in:
@@ -575,7 +575,7 @@ api.getChallenge = {
|
||||
|
||||
// Fetching basic group data
|
||||
const group = await Group.getGroup({
|
||||
user, groupId: challenge.group, fields: `${basicGroupFields} purchased`, optionalMembership: true,
|
||||
user, groupId: challenge.group, fields: `${basicGroupFields} purchased`,
|
||||
});
|
||||
if (!group && !challenge.canView(user, group)) throw new NotFound(res.t('challengeNotFound'));
|
||||
const chalRes = challenge.toJSON();
|
||||
|
||||
Reference in New Issue
Block a user