Changed the API to not export saved Message instances (they can contain information such as draft confirmation codes and password reset codes that should not be generally visible).

- Legacy-Id: 18375
This commit is contained in:
Henrik Levkowetz 2020-08-15 09:37:05 +00:00
parent 50d559f05f
commit f93270e0f6

View file

@ -22,7 +22,7 @@ class MessageResource(ModelResource):
related_docs = ToManyField(DocumentResource, 'related_docs', null=True)
class Meta:
cache = SimpleCache()
queryset = Message.objects.all()
queryset = Message.objects.none()
serializer = api.Serializer()
#resource_name = 'message'
ordering = ['id', ]
@ -69,7 +69,7 @@ api.message.register(SendQueueResource())
class MessageAttachmentResource(ModelResource):
message = ToOneField(MessageResource, 'message')
class Meta:
queryset = MessageAttachment.objects.all()
queryset = MessageAttachment.objects.none()
serializer = api.Serializer()
cache = SimpleCache()
#resource_name = 'messageattachment'