commit: b65eb00c53af939444e0e891c0a3a4563f4897ac
parent b5726def55994db8eb5797bbea1d2b79df3e884a
Author: Alda Marteau-Hardi <github@ltch.fr>
Date: Sat, 7 Apr 2018 21:33:01 +0200
Prevent admins and moderators eavesdropping in private and direct toots (#7067)
Fix #6986
Diffstat:
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/app/controllers/admin/statuses_controller.rb b/app/controllers/admin/statuses_controller.rb
@@ -12,7 +12,7 @@ module Admin
def index
authorize :status, :index?
- @statuses = @account.statuses
+ @statuses = @account.statuses.where(visibility: [:public, :unlisted])
if params[:media]
account_media_status_ids = @account.media_attachments.attached.reorder(nil).select(:status_id).distinct