From 3deac8edfba8e8088de855789a28e7d3a328b9b5 Mon Sep 17 00:00:00 2001 From: Carl Eberhard Date: Mon, 28 Jan 2013 16:20:49 -0500 Subject: [PATCH] History grid, view: allow user to view their own histories --- lib/galaxy/webapps/galaxy/controllers/history.py | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/galaxy/webapps/galaxy/controllers/history.py b/lib/galaxy/webapps/galaxy/controllers/history.py index 72ff15c7807..28028507402 100644 --- a/lib/galaxy/webapps/galaxy/controllers/history.py +++ b/lib/galaxy/webapps/galaxy/controllers/history.py @@ -847,7 +847,9 @@ class HistoryController( BaseUIController, SharableMixin, UsesAnnotations, UsesI if not history_to_view: return trans.show_error_message( "The specified history does not exist." ) # Admin users can view any history - if not trans.user_is_admin() and not history_to_view.importable: + if( ( history_to_view.user != trans.user ) + and ( not trans.user_is_admin() ) + and ( not history_to_view.importable ) ): error( "Either you are not allowed to view this history or the owner of this history has not made it accessible." ) # View history. show_deleted = util.string_as_bool( show_deleted )