Javi Martín
d1d71f0044
Don't allow valuation if cannot edit dossier
...
We were adding the condition to show the form in the view. However, that
doesn't prevent users from sending a POST/PUT request to the controller
action.
We could add the condition to the controller as well, but since the
`valuate` permission is only used in one place, it's easier to restrict
that permission to valuators who can edit the dossier.
2019-11-05 23:15:16 +01:00
..
2019-11-05 23:15:16 +01:00
2019-09-23 16:51:00 +02:00
2019-10-25 23:17:49 +02:00
2019-10-26 20:10:33 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-30 02:26:42 +01:00
2019-10-26 13:03:49 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-30 18:48:55 +01:00
2019-09-23 18:01:44 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-11-01 17:12:42 +01:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:56:03 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-05-31 18:22:59 +02:00
2019-10-05 14:44:14 +02:00
2019-02-15 11:40:39 +01:00
2019-10-24 17:11:47 +02:00
2019-03-27 15:22:14 +01:00
2019-09-29 23:57:35 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-10 02:35:20 +02:00
2019-10-30 21:15:05 +01:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-23 14:39:31 +02:00
2019-10-24 17:11:47 +02:00
2019-10-26 13:37:36 +02:00
2019-10-20 15:03:05 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-05-21 13:50:18 +02:00
2019-05-21 13:50:19 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00
2019-10-24 17:11:47 +02:00