From b3f54962abeb941a24e05527754bea523ef2fe14 Mon Sep 17 00:00:00 2001 From: "ashutosh.nehete" Date: Wed, 1 Oct 2025 10:55:00 +0530 Subject: [PATCH] Removed hasProjectAccess check from document controller --- .../Controllers/DocumentController.cs | 28 +++++++++---------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/Marco.Pms.Services/Controllers/DocumentController.cs b/Marco.Pms.Services/Controllers/DocumentController.cs index 4c3d49a..c3b219f 100644 --- a/Marco.Pms.Services/Controllers/DocumentController.cs +++ b/Marco.Pms.Services/Controllers/DocumentController.cs @@ -95,16 +95,16 @@ namespace Marco.Pms.Services.Controllers return NotFound(ApiResponse.ErrorResponse("Entity type not found", "Entity Type not found in database", 404)); } - // Project permission check - if (ProjectEntity == entityTypeId) - { - var hasProjectPermission = await _permission.HasProjectPermission(loggedInEmployee, entityId); - if (!hasProjectPermission) - { - _logger.LogWarning("Employee {EmployeeId} does not have project access for ProjectId {ProjectId}", loggedInEmployee.Id, entityId); - return StatusCode(403, ApiResponse.ErrorResponse("Access Denied.", "You do not have permission to access project documents", 403)); - } - } + //// Project permission check + //if (ProjectEntity == entityTypeId) + //{ + // var hasProjectPermission = await _permission.HasProjectPermission(loggedInEmployee, entityId); + // if (!hasProjectPermission) + // { + // _logger.LogWarning("Employee {EmployeeId} does not have project access for ProjectId {ProjectId}", loggedInEmployee.Id, entityId); + // return StatusCode(403, ApiResponse.ErrorResponse("Access Denied.", "You do not have permission to access project documents", 403)); + // } + //} // Employee validation else if (EmployeeEntity == entityTypeId) { @@ -1085,10 +1085,10 @@ namespace Marco.Pms.Services.Controllers else if (entityType.Equals(ProjectEntity)) { entityExists = await _context.Projects.AnyAsync(p => p.Id == oldAttachment.EntityId && p.TenantId == tenantId); - if (entityExists) - { - entityExists = await _permission.HasProjectPermission(loggedInEmployee, oldAttachment.EntityId); - } + //if (entityExists) + //{ + // entityExists = await _permission.HasProjectPermission(loggedInEmployee, oldAttachment.EntityId); + //} } else {