SignupAuthentication canAddOthers for admin

This commit is contained in:
quentin 2024-10-29 19:13:15 -05:00
parent 048ccd7c4c
commit d48186d4d6
2 changed files with 7 additions and 4 deletions

View File

@ -10,5 +10,6 @@ namespace API.Authentication.GrantNames
public const string CanUpdate = "api.signup.update"; public const string CanUpdate = "api.signup.update";
public const string CanDeleteAny = "api.signup.delete.any"; public const string CanDeleteAny = "api.signup.delete.any";
public const string CanDelete = "api.signup.delete"; public const string CanDelete = "api.signup.delete";
public const string CanAddOthers = "api.signup.add.others";
} }
} }

View File

@ -30,7 +30,9 @@ namespace API.Authentication
} }
public bool canAdd(SignupDTO item, User user) public bool canAdd(SignupDTO item, User user)
{ {
if (item.userId == user.id)
return _grantManager.hasGrant(user.permissionId, SignupGrantNames.CanAdd); return _grantManager.hasGrant(user.permissionId, SignupGrantNames.CanAdd);
return _grantManager.hasGrant(user.permissionId, SignupGrantNames.CanAddOthers);
} }
public bool canUpdate(Signup model, User user) public bool canUpdate(Signup model, User user)
{ {