allow API access for logged in users

makes the "browsable API" useful

......@@ -138,7 +138,9 @@ class InvitationUpdateView(UpdateView):
class TokenPermission(BasePermission):
def has_permission(self, request, view):
return request.headers.get('Authorization') == 'token ' + settings.API_TOKEN
token = request.headers.get('Authorization') == 'token ' + settings.API_TOKEN
is_authenticated = bool(request.user and request.user.is_authenticated)
return token or is_authenticated
class InvitationApiView(APIView):
