We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent fa487ed commit 5e4357cCopy full SHA for 5e4357c
internal/api/albums.go
@@ -70,7 +70,7 @@ func GetAlbum(router *gin.RouterGroup) {
70
}
71
72
// Other restricted users can only access their own or shared content.
73
- if album.CreatedBy != s.UserUID && s.User().HasSharedAccessOnly(acl.ResourceAlbums) {
+ if s.User().HasSharedAccessOnly(acl.ResourceAlbums) && album.CreatedBy != s.UserUID && !s.HasShare(uid) {
74
AbortForbidden(c)
75
return
76
0 commit comments