diff --git a/app/controllers/api/submissions_controller.rb b/app/controllers/api/submissions_controller.rb index 7c00f0f3..af784ba2 100644 --- a/app/controllers/api/submissions_controller.rb +++ b/app/controllers/api/submissions_controller.rb @@ -112,7 +112,7 @@ module Api submissions = submissions.where(slug: params[:slug]) if params[:slug].present? if params[:template_folder].present? - folder = TemplateFolder.find_by(name: params[:template_folder], account_id: current_user.account_id) + folder = TemplateFolder.accessible_by(current_ability).find_by(name: params[:template_folder]) submissions = folder ? submissions.joins(:template).where(template: { folder_id: folder.id }) : submissions.none end