We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent ea3937e commit ba062bbCopy full SHA for ba062bb
1 file changed
backend/controllers/itemController.js
@@ -54,7 +54,7 @@ module.exports = {
54
55
// Check session's read authority
56
const user = await userService.findOne({ serviceNumber: res.locals.serviceNumber });
57
- if(!item.accessGroups.read.some(i => i.equals(user.group)) && item.owner._id !== res.locals._id)
+ if(!item.accessGroups.read.some(i => i.equals(user.group)) && item.owner._id.toString() !== res.locals._id.toString())
58
throw new ForbiddenError(`Access denied: 열람 권한이 없습니다.`);
59
60
res.status(200).send(item);
0 commit comments