Skip to content

Commit 53b257e

Browse files
committed
Don't leak information about events the user can't see
1 parent e06202e commit 53b257e

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

outlook/indico_outlook/plugin.py

+2-1
Original file line numberDiff line numberDiff line change
@@ -209,7 +209,8 @@ def event_updated(self, event, changes, **kwargs):
209209
# Now look for users that have marked as favorite that event's category (or any of its parents)
210210
for category in event.category.chain_query.all():
211211
for user in category.favorite_of:
212-
users_to_update.add(user)
212+
if event.can_access(user):
213+
users_to_update.add(user)
213214

214215
for user in users_to_update:
215216
self.logger.info('Event data change: updating %s in %r', user, event)

0 commit comments

Comments
 (0)