mirror of
https://github.com/stonith404/pingvin-share.git
synced 2024-06-30 14:40:10 +02:00
fix: reverse shares couldn't be created unauthenticated
This commit is contained in:
parent
5503e7a54f
commit
966ce261cb
|
@ -19,7 +19,6 @@ export class ShareOwnerGuard extends JwtGuard {
|
||||||
}
|
}
|
||||||
|
|
||||||
async canActivate(context: ExecutionContext) {
|
async canActivate(context: ExecutionContext) {
|
||||||
if (!(await super.canActivate(context))) return false;
|
|
||||||
|
|
||||||
const request: Request = context.switchToHttp().getRequest();
|
const request: Request = context.switchToHttp().getRequest();
|
||||||
const shareId = Object.prototype.hasOwnProperty.call(
|
const shareId = Object.prototype.hasOwnProperty.call(
|
||||||
|
@ -38,6 +37,8 @@ export class ShareOwnerGuard extends JwtGuard {
|
||||||
|
|
||||||
if (!share.creatorId) return true;
|
if (!share.creatorId) return true;
|
||||||
|
|
||||||
|
if (!(await super.canActivate(context))) return false;
|
||||||
|
|
||||||
return share.creatorId == (request.user as User).id;
|
return share.creatorId == (request.user as User).id;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue
Block a user