mirror of
https://github.com/kremalicious/umami.git
synced 2024-12-18 15:23:38 +01:00
Fix password change issue for non-admin accounts.
This commit is contained in:
parent
0654b7b873
commit
1b172d214b
@ -9,7 +9,7 @@ export default async (req, res) => {
|
|||||||
const { user_id: auth_user_id, is_admin } = req.auth;
|
const { user_id: auth_user_id, is_admin } = req.auth;
|
||||||
const { user_id, current_password, new_password } = req.body;
|
const { user_id, current_password, new_password } = req.body;
|
||||||
|
|
||||||
if (!is_admin || user_id !== auth_user_id) {
|
if (!is_admin && user_id !== auth_user_id) {
|
||||||
return unauthorized(res);
|
return unauthorized(res);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user