diff --git a/app/controllers/api/service/base_controller.rb b/app/controllers/api/service/base_controller.rb index ec0be0f9c..3640ce881 100644 --- a/app/controllers/api/service/base_controller.rb +++ b/app/controllers/api/service/base_controller.rb @@ -73,6 +73,7 @@ module Api def load_team @team = current_user.teams.find(params.require(:team_id)) + current_user.permission_team = @team raise PermissionError.new(Team, :read) unless can_read_team?(@team) end