Change the check permssion check for tenant details API
This commit is contained in:
parent
a684556cff
commit
68aec35028
@ -290,7 +290,7 @@ namespace Marco.Pms.Services.Controllers
|
|||||||
}
|
}
|
||||||
_logger.LogInfo("Tenant {TenantId} found.", tenant.Id);
|
_logger.LogInfo("Tenant {TenantId} found.", tenant.Id);
|
||||||
|
|
||||||
if (!hasManagePermission && (tenant.OrganizationId != loggedInEmployee.OrganizationId && !(hasModifyPermission || hasViewPermission)))
|
if (!hasManagePermission && (tenant.OrganizationId != loggedInEmployee.OrganizationId || (!hasModifyPermission && !hasViewPermission)))
|
||||||
{
|
{
|
||||||
_logger.LogWarning("Permission denied: User {EmployeeId} attempted to access tenant details of other tenant.", loggedInEmployee.Id);
|
_logger.LogWarning("Permission denied: User {EmployeeId} attempted to access tenant details of other tenant.", loggedInEmployee.Id);
|
||||||
return StatusCode(403,
|
return StatusCode(403,
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user