diff --git a/scipost_django/pins/managers.py b/scipost_django/pins/managers.py index 483504b966b24783e1d4292f749ca1cb73ece87e..4387f4e2d3cb0567a40f033e2b13c9fe35422369 100644 --- a/scipost_django/pins/managers.py +++ b/scipost_django/pins/managers.py @@ -18,7 +18,7 @@ class NotesQuerySet(models.QuerySet): Filter out notes which are not visible to the given user. """ - if user is None: + if user is None or not user.is_authenticated: # Without specifying a user, only public notes are visible return self.filter(visibility=self.model.VISIBILITY_PUBLIC) else: