mirror of
https://github.com/sasjs/server.git
synced 2025-12-10 19:34:34 +00:00
chore: swagger authentication added
This commit is contained in:
@@ -8,7 +8,8 @@ import {
|
||||
Patch,
|
||||
Delete,
|
||||
Body,
|
||||
Hidden
|
||||
Hidden,
|
||||
Security
|
||||
} from 'tsoa'
|
||||
import bcrypt from 'bcryptjs'
|
||||
|
||||
@@ -28,7 +29,8 @@ interface userDetailsResponse {
|
||||
isAdmin: boolean
|
||||
}
|
||||
|
||||
@Route('user')
|
||||
@Security('bearerAuth')
|
||||
@Route('SASjsApi/user')
|
||||
export default class UserController {
|
||||
/**
|
||||
* Get list of all users (username, displayname). All users can request this.
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
export const verifyAdminIfNeeded = (req: any, res: any, next: any) => {
|
||||
const { user } = req
|
||||
const { userId } = req.params
|
||||
const userId = parseInt(req.params.userId)
|
||||
|
||||
if (!user.isAdmin && user.id !== userId) {
|
||||
if (!user.isAdmin && user.userId !== userId) {
|
||||
return res.status(401).send('Admin account required')
|
||||
}
|
||||
next()
|
||||
|
||||
Reference in New Issue
Block a user