Skip to content
Discussion options

You must be logged in to vote

You need to write access control to restrict who can see documents with status: '_draft'.

The ?draft=true REST query parameter is only responsible for replacing documents' contents with their newest draft content and does not have any restrictions around who can see the documents returned vs. who can't. That's a job for access control.

Take a look at the docs here:
https://payloadcms.com/docs/versions/drafts#controlling-who-can-see-collection-drafts

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by adam-mrozik
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants