Closed PetrDlouhy closed 1 year ago
@bufke @pedrovhb I will leave this PR open for few days, if you want to review it yourself. After that I will merge them.
BTW. There might be even more cases of calls that should use the admin_obj
.
Looks good to me :slightly_smiling_face:
When
mass_change_view()
calls theget_queryset()
function from self, it is in fact calling the genericModelView.get_queryset()
which results in the view not respecting the user implementation and potentially exposing models not permitted for editation.This is related to #103