X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/7aaf9f22aa646077b4b7fd961d6b731185b88137..df8aa6da0173f77aa9f2fcbe2814a07bcdcbf5d9:/services/api/app/controllers/arvados/v1/users_controller.rb diff --git a/services/api/app/controllers/arvados/v1/users_controller.rb b/services/api/app/controllers/arvados/v1/users_controller.rb index 54db521768..507cb4ac33 100644 --- a/services/api/app/controllers/arvados/v1/users_controller.rb +++ b/services/api/app/controllers/arvados/v1/users_controller.rb @@ -274,7 +274,7 @@ class Arvados::V1::UsersController < ApplicationController return super if @read_users.any?(&:is_admin) if params[:uuid] != current_user.andand.uuid # Non-admin index/show returns very basic information about readable users. - safe_attrs = ["uuid", "is_active", "email", "first_name", "last_name", "username"] + safe_attrs = ["uuid", "is_active", "email", "first_name", "last_name", "username", "can_write", "can_manage"] if @select @select = @select & safe_attrs else