diff --git a/core/viewsets.py b/core/viewsets.py index 10647fea..af3a123a 100644 --- a/core/viewsets.py +++ b/core/viewsets.py @@ -377,6 +377,15 @@ class OrderProductViewSet(EvibesViewSet): "list": OrderProductSimpleSerializer, } + def get_queryset(self): + qs = super().get_queryset() + user = self.request.user + + if user.has_perm("core.view_orderproduct"): + return qs + + return qs.filter(user=user) + class ProductImageViewSet(EvibesViewSet): queryset = ProductImage.objects.all() @@ -397,6 +406,15 @@ class PromoCodeViewSet(EvibesViewSet): "list": PromoCodeSimpleSerializer, } + def get_queryset(self): + qs = super().get_queryset() + user = self.request.user + + if user.has_perm("core.view_promocode"): + return qs + + return qs.filter(user=user) + class PromotionViewSet(EvibesViewSet): queryset = Promotion.objects.all()