From bdebcf319e26dc6e2083175b046d67aef2d254c6 Mon Sep 17 00:00:00 2001 From: Sebastian Serth Date: Thu, 25 Aug 2022 18:14:10 +0200 Subject: [PATCH] Allow access to user statistics for teachers Fixes CODEOCEAN-BV --- app/controllers/external_users_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/external_users_controller.rb b/app/controllers/external_users_controller.rb index ff134cfd..18a287c2 100644 --- a/app/controllers/external_users_controller.rb +++ b/app/controllers/external_users_controller.rb @@ -45,7 +45,7 @@ class ExternalUsersController < ApplicationController FROM submissions WHERE #{ExternalUser.sanitize_sql(['user_id = ?', @user.id])} AND user_type = 'ExternalUser' - #{current_user.admin? ? '' : "AND #{ExternalUser.sanitize_sql(['study_group_id IN (?)', current_user.study_groups.pluck(:id).join(', ')])} AND cause = 'submit'"} + #{current_user.admin? ? '' : "AND #{ExternalUser.sanitize_sql(['study_group_id IN (?)', current_user.study_groups.pluck(:id)])} AND cause = 'submit'"} GROUP BY exercise_id, user_id, id