]> git.ipfire.org Git - thirdparty/paperless-ngx.git/commitdiff
Fix: prevent note deletion outside doc
authorshamoon <4887959+shamoon@users.noreply.github.com>
Thu, 29 Jan 2026 21:29:30 +0000 (13:29 -0800)
committershamoon <4887959+shamoon@users.noreply.github.com>
Thu, 29 Jan 2026 21:35:01 +0000 (13:35 -0800)
src/documents/views.py

index a91ad8594b1dc7737a9d1a3c38e2be0644933863..f6bec1f0d7a7e3e3f58307c441b11e31556c9c60 100644 (file)
@@ -1099,7 +1099,7 @@ class DocumentViewSet(
             ):
                 return HttpResponseForbidden("Insufficient permissions to delete notes")
 
-            note = Note.objects.get(id=int(request.GET.get("id")))
+            note = Note.objects.get(id=int(request.GET.get("id")), document=doc)
             if settings.AUDIT_LOG_ENABLED:
                 LogEntry.objects.log_create(
                     instance=doc,