add manage user permission
This commit is contained in:
@@ -105,13 +105,13 @@ function tokenAuth(req, res, next) {
|
||||
});
|
||||
}
|
||||
|
||||
function authorize(requiredRole) {
|
||||
assert.strictEqual(typeof requiredRole, 'string');
|
||||
function authorize(requiredPermission) {
|
||||
assert.strictEqual(typeof requiredPermission, 'string');
|
||||
|
||||
return function (req, res, next) {
|
||||
assert.strictEqual(typeof req.user, 'object');
|
||||
|
||||
var error = accesscontrol.hasRole(req.user, requiredRole);
|
||||
var error = accesscontrol.hasPermission(req.user, requiredPermission);
|
||||
if (error) return next(new HttpError(403, error.message));
|
||||
|
||||
next();
|
||||
|
||||
Reference in New Issue
Block a user