fix: only check event type ownership if not admin
parent
0fc374c810
commit
0eed3e51e4
|
@ -27,10 +27,9 @@ export async function eventTypeById(
|
|||
select: { eventTypes: true },
|
||||
});
|
||||
const userEventTypes = data.eventTypes.map((eventType) => eventType.id);
|
||||
|
||||
if (!isAdmin || !userEventTypes.includes(safeQuery.data.id))
|
||||
res.status(401).json({ message: "Unauthorized" });
|
||||
else {
|
||||
if (!isAdmin) {
|
||||
if (!userEventTypes.includes(safeQuery.data.id)) res.status(401).json({ message: "Unauthorized" });
|
||||
} else {
|
||||
switch (method) {
|
||||
/**
|
||||
* @swagger
|
||||
|
|
Loading…
Reference in New Issue