wushaodong 4 лет назад
Родитель
Сommit
687f4b6819
1 измененных файлов с 2 добавлено и 1 удалено
  1. 2 1
      apps/order/views.py

+ 2 - 1
apps/order/views.py

@@ -12,7 +12,7 @@ from .filters import OrderFilter
 from apps.log.models import BizLog
 from django.db.models import Q
 from utils import response_ok, response_error
-from utils.permission import isLogin, check_permission
+from utils.permission import isLogin, check_permission, permission_required
 from apps.customer.models import NewCustomer, NewCustomerRemind
 from apps.order.models import Order, ProgressDetails
 from apps.option.models import Option
@@ -64,6 +64,7 @@ class OrderViewSet(CustomModelViewSet):
     queryset = Order.objects.filter()
     serializer_class = OrderSerializer
 
+    @permission_required('order.view_order')
     def filter_queryset(self, queryset):
         queryset = queryset.filter(
             Q(store_id__in=self.request.user.get_manager_range()) |