diff --git a/app/controllers/projects/filters_controller.rb b/app/controllers/projects/filters_controller.rb index 54f82f3228a..1ff9de5d501 100644 --- a/app/controllers/projects/filters_controller.rb +++ b/app/controllers/projects/filters_controller.rb @@ -32,7 +32,9 @@ class Projects::FiltersController < ApplicationController # include QueriesHelper include Queries::Loading - before_action :require_admin # to be adapted + # This is a part of the projects list page which is public. Checks within filters will + # prevent sensitive information to be displayed wrongfully. + no_authorization_required! :show before_action :load_query_or_deny_access def show