Restrict delete user API endpoint to MT+ level (CC-67)
parent
ac83629824
commit
2c996a14e2
|
@ -9,6 +9,7 @@ const codes = require('./http-codes');
|
|||
|
||||
const apiAuthenticationMiddleware = require('../middleware/auth-middleware');
|
||||
const checkHl = require('../middleware/permission-check').checkHl;
|
||||
const checkMT = require('../middleware/permission-check').checkMT;
|
||||
|
||||
const offsetlimitMiddleware = require('../middleware/limitoffset-middleware-mongo');
|
||||
const filterHandlerCreator = require('../middleware/filter-handler-mongo');
|
||||
|
@ -180,7 +181,7 @@ users.route('/:id')
|
|||
});
|
||||
})
|
||||
|
||||
.delete(apiAuthenticationMiddleware, checkHl, (req, res, next) => {
|
||||
.delete(apiAuthenticationMiddleware, checkMT, (req, res, next) => {
|
||||
UserModel.findByIdAndRemove(req.params.id, (err, item) => {
|
||||
if (err) {
|
||||
err.status = codes.wrongrequest;
|
||||
|
|
Loading…
Reference in New Issue