From 8edfd1c3552feebab3e7b5ba86886634f6526c09 Mon Sep 17 00:00:00 2001 From: richard-dds Date: Tue, 30 Jul 2019 14:24:07 -0400 Subject: [PATCH] Restrict access to edit route --- atst/routes/task_orders/new.py | 1 + 1 file changed, 1 insertion(+) diff --git a/atst/routes/task_orders/new.py b/atst/routes/task_orders/new.py index fd358429..43736e1a 100644 --- a/atst/routes/task_orders/new.py +++ b/atst/routes/task_orders/new.py @@ -57,6 +57,7 @@ def update_task_order( @task_orders_bp.route("/task_orders//edit") +@user_can(Permissions.CREATE_TASK_ORDER, message="edit task order form") def edit(task_order_id): task_order = TaskOrders.get(task_order_id)