diff options
author | Marius Balteanu <marius.balteanu@zitec.com> | 2021-09-06 18:40:14 +0000 |
---|---|---|
committer | Marius Balteanu <marius.balteanu@zitec.com> | 2021-09-06 18:40:14 +0000 |
commit | 1e65114d6894d7ce1ae6b7931d32e142971235c4 (patch) | |
tree | 1f80af0abcc5b3a16560333d84907c211ca7e493 /app | |
parent | 55ce8de0aea23397aafdee68e4e7be1beb6089a9 (diff) | |
download | redmine-1e65114d6894d7ce1ae6b7931d32e142971235c4.tar.gz redmine-1e65114d6894d7ce1ae6b7931d32e142971235c4.zip |
Return 404 when filtering by a non-visible user in activity view (#35789).
Patch by Mischa The Evil.
git-svn-id: http://svn.redmine.org/redmine/trunk@21209 e93f8b46-1217-0410-a6f0-8f06a7374b81
Diffstat (limited to 'app')
-rw-r--r-- | app/controllers/activities_controller.rb | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/app/controllers/activities_controller.rb b/app/controllers/activities_controller.rb index cce17aef2..824aaa2ef 100644 --- a/app/controllers/activities_controller.rb +++ b/app/controllers/activities_controller.rb @@ -33,7 +33,7 @@ class ActivitiesController < ApplicationController @date_from = @date_to - @days @with_subprojects = params[:with_subprojects].nil? ? Setting.display_subprojects_issues? : (params[:with_subprojects] == '1') if params[:user_id].present? - @author = User.active.find(params[:user_id]) + @author = User.visible.active.find(params[:user_id]) end @activity = Redmine::Activity::Fetcher.new(User.current, :project => @project, |