From 68aec3502870e164ea2bb7b65190babcb64b9d33 Mon Sep 17 00:00:00 2001 From: "ashutosh.nehete" Date: Fri, 31 Oct 2025 11:26:45 +0530 Subject: [PATCH] Change the check permssion check for tenant details API --- Marco.Pms.Services/Controllers/TenantController.cs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Marco.Pms.Services/Controllers/TenantController.cs b/Marco.Pms.Services/Controllers/TenantController.cs index 80366ab..8523ebb 100644 --- a/Marco.Pms.Services/Controllers/TenantController.cs +++ b/Marco.Pms.Services/Controllers/TenantController.cs @@ -290,7 +290,7 @@ namespace Marco.Pms.Services.Controllers } _logger.LogInfo("Tenant {TenantId} found.", tenant.Id); - if (!hasManagePermission && (tenant.OrganizationId != loggedInEmployee.OrganizationId && !(hasModifyPermission || hasViewPermission))) + if (!hasManagePermission && (tenant.OrganizationId != loggedInEmployee.OrganizationId || (!hasModifyPermission && !hasViewPermission))) { _logger.LogWarning("Permission denied: User {EmployeeId} attempted to access tenant details of other tenant.", loggedInEmployee.Id); return StatusCode(403,