From dc9bcf3d53a46c50db42b3afb9c99bc2d508ad61 Mon Sep 17 00:00:00 2001 From: Jan-Hendrik Willms Date: Thu, 29 Jan 2026 15:48:23 +0100 Subject: jsonapi: allow root to index a user's course memberships as well, fixes #6206 Closes #6206 Merge request studip/studip!4698 --- lib/classes/JsonApi/Routes/Courses/Authority.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/lib/classes/JsonApi/Routes/Courses/Authority.php b/lib/classes/JsonApi/Routes/Courses/Authority.php index 05a3cc8..42f36b6 100644 --- a/lib/classes/JsonApi/Routes/Courses/Authority.php +++ b/lib/classes/JsonApi/Routes/Courses/Authority.php @@ -54,6 +54,7 @@ class Authority public static function canIndexMembershipsOfUser(User $observer, User $user) { - return $observer->id === $user->id; + return $observer->id === $user->id + || $GLOBALS['perm']->have_perm('root', $observer->id); } } -- cgit v1.0