Tighten permissions checking on modmail responses

Prevents users who don't have permission to see a mail
thread from submitting replies to it.
This commit is contained in:
Keith Mitchell
2012-11-12 11:28:27 -08:00
parent 6d6c8335a0
commit b1a3c00568

View File

@@ -1001,6 +1001,8 @@ class ApiController(RedditController, OAuth2ResourceController):
if isinstance(parent, Message):
if not getattr(parent, "repliable", True):
abort(403, 'forbidden')
if not parent.can_view_slow():
abort(403, 'forbidden')
is_message = True
should_ratelimit = False
else: