From d41366a4177250356f3bb1148777e09c003c91b1 Mon Sep 17 00:00:00 2001 From: advplyr Date: Mon, 28 Nov 2022 16:29:04 -0600 Subject: [PATCH] Fix:Playlist API endpoint permissions --- server/controllers/PlaylistController.js | 8 -------- 1 file changed, 8 deletions(-) diff --git a/server/controllers/PlaylistController.js b/server/controllers/PlaylistController.js index 89d11791..ecabb686 100644 --- a/server/controllers/PlaylistController.js +++ b/server/controllers/PlaylistController.js @@ -187,14 +187,6 @@ class PlaylistController { req.playlist = playlist } - if (req.method == 'DELETE' && !req.user.canDelete) { - Logger.warn(`[PlaylistController] User attempted to delete without permission`, req.user.username) - return res.sendStatus(403) - } else if ((req.method == 'PATCH' || req.method == 'POST') && !req.user.canUpdate) { - Logger.warn('[PlaylistController] User attempted to update without permission', req.user.username) - return res.sendStatus(403) - } - next() } }