X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/18d976b4701d76bdeb05e0fe3c1757060d3b8a2a..9551b59d3aab67f77240b90bbb550faec6b2a7d9:/services/api/app/controllers/arvados/v1/users_controller.rb diff --git a/services/api/app/controllers/arvados/v1/users_controller.rb b/services/api/app/controllers/arvados/v1/users_controller.rb index 54db521768..507cb4ac33 100644 --- a/services/api/app/controllers/arvados/v1/users_controller.rb +++ b/services/api/app/controllers/arvados/v1/users_controller.rb @@ -274,7 +274,7 @@ class Arvados::V1::UsersController < ApplicationController return super if @read_users.any?(&:is_admin) if params[:uuid] != current_user.andand.uuid # Non-admin index/show returns very basic information about readable users. - safe_attrs = ["uuid", "is_active", "email", "first_name", "last_name", "username"] + safe_attrs = ["uuid", "is_active", "email", "first_name", "last_name", "username", "can_write", "can_manage"] if @select @select = @select & safe_attrs else