diff --git a/inventory-app/inventory.py b/inventory-app/inventory.py index 2a5be19..2d3a774 100644 --- a/inventory-app/inventory.py +++ b/inventory-app/inventory.py @@ -20,12 +20,15 @@ db = MongoClient(const.MONGO_URI).get_default_database() @page_inventory.route("/m/inventory//view") def view_inventory_view(item_id): + user = read_user() template = "inventory_view.html" item = db.inventory.find_one({ "_id": ObjectId(item_id) }) - if not read_user(): + if not user: if not item["inventory"].get("public"): return do_login() template = "inventory_view_public.html" + else: + can_audit = "k-space:janitors" in user["groups"] bucket=get_bucket() photo_url = bucket.generate_presigned_url( ClientMethod='get_object',