Skip to content

Commit 3ee65cd

Browse files
committed
Fix for limited and protected permissions should forbid guest in realtime events
1 parent 4851098 commit 3ee65cd

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

lib/realtime.js

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -374,7 +374,7 @@ function finishConnection(socket, note, user) {
374374
return interruptConnection(socket, note, user);
375375
}
376376
//check view permission
377-
if (note.permission == 'private') {
377+
if (note.permission == 'limited' || note.permission == 'protected' || note.permission == 'private') {
378378
if (socket.request.user && socket.request.user.logged_in && socket.request.user.id == note.owner) {
379379
//na
380380
} else {
@@ -790,7 +790,7 @@ function connection(socket) {
790790
var sock = note.socks[i];
791791
if (typeof sock !== 'undefined' && sock) {
792792
//check view permission
793-
if (permission == 'private') {
793+
if (permission == 'limited' || permission == 'protected' || permission == 'private') {
794794
if (sock.request.user && sock.request.user.logged_in && sock.request.user.id == note.owner) {
795795
//na
796796
} else {

0 commit comments

Comments
 (0)