diff --git a/app/Http/Controllers/BaseController.php b/app/Http/Controllers/BaseController.php index a2695f0c6d20..83b99932aafb 100644 --- a/app/Http/Controllers/BaseController.php +++ b/app/Http/Controllers/BaseController.php @@ -773,7 +773,8 @@ class BaseController extends Controller // 10-01-2022 need to ensure we snake case properly here to ensure permissions work as expected // 28-03-2022 this is definitely correct here, do not append _ to the view, it resolved correctly when snake cased if (auth()->user() && ! auth()->user()->hasPermission('view'.lcfirst(class_basename(Str::snake($this->entity_type))))) { - $query->where('user_id', '=', auth()->user()->id); + //03-09-2022 + $query->where('user_id', '=', auth()->user()->id)->orWhere('assigned_user_id', auth()->user()->id); } if (request()->has('updated_at') && request()->input('updated_at') > 0) {