Change the check permssion check for tenant details API

This commit is contained in:
ashutosh.nehete 2025-10-31 11:26:45 +05:30
parent a684556cff
commit 68aec35028

View File

@ -290,7 +290,7 @@ namespace Marco.Pms.Services.Controllers
} }
_logger.LogInfo("Tenant {TenantId} found.", tenant.Id); _logger.LogInfo("Tenant {TenantId} found.", tenant.Id);
if (!hasManagePermission && (tenant.OrganizationId != loggedInEmployee.OrganizationId && !(hasModifyPermission || hasViewPermission))) if (!hasManagePermission && (tenant.OrganizationId != loggedInEmployee.OrganizationId || (!hasModifyPermission && !hasViewPermission)))
{ {
_logger.LogWarning("Permission denied: User {EmployeeId} attempted to access tenant details of other tenant.", loggedInEmployee.Id); _logger.LogWarning("Permission denied: User {EmployeeId} attempted to access tenant details of other tenant.", loggedInEmployee.Id);
return StatusCode(403, return StatusCode(403,