The security checker was broken recently: return self.obj.person == user or user.in_admin should be return self.obj.person == user.person or user.in_admin
The tests passed because the user salgado is an admin.
The security checker was broken recently:
return self.obj.person == user or user.in_admin
should be
return self.obj.person == user.person or user.in_admin
The tests passed because the user salgado is an admin.