Entering "ga" always opens a user's assignments, even when they can't access them

This is reproducible anywhere with Discourse assign, including here. Just enter ga when not in a text box and the bind triggers, regardless if you’re allowed to do so or not.

3 Likes

Good catch :+1:

That line might need to be moved inside a api.getCurrentUser()?.can_assign condition.

4 Likes