Signed-off-by: Andrew Thornton <art27@cantab.net>tags/v1.13.0-rc2
@@ -56,7 +56,11 @@ func GetIssueCommentReactions(ctx *context.APIContext) { | |||
return | |||
} | |||
if !ctx.Repo.CanRead(models.UnitTypeIssues) { | |||
if err := comment.LoadIssue(); err != nil { | |||
ctx.Error(http.StatusInternalServerError, "comment.LoadIssue", err) | |||
} | |||
if !ctx.Repo.CanReadIssuesOrPulls(comment.Issue.IsPull) { | |||
ctx.Error(http.StatusForbidden, "GetIssueCommentReactions", errors.New("no permission to get reactions")) | |||
return | |||
} |