X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/379717415ec5f772ab2f54e263c2c3f44d77f70f..a12864a31d5569c74ed32157d5fe928a1c2563b7:/services/api/app/controllers/arvados/v1/users_controller.rb diff --git a/services/api/app/controllers/arvados/v1/users_controller.rb b/services/api/app/controllers/arvados/v1/users_controller.rb index 03efed999f..db5e7bd952 100644 --- a/services/api/app/controllers/arvados/v1/users_controller.rb +++ b/services/api/app/controllers/arvados/v1/users_controller.rb @@ -159,7 +159,7 @@ class Arvados::V1::UsersController < ApplicationController end def apply_filters(model_class=nil) - return super if @read_users.any? &:is_admin + return super if @read_users.any?(&:is_admin) if params[:uuid] != current_user.andand.uuid # Non-admin index/show returns very basic information about readable users. safe_attrs = ["uuid", "is_active", "email", "first_name", "last_name"]