From fc7414cce66f659c3e52cb02bdfd87d399bf1a43 Mon Sep 17 00:00:00 2001 From: Girish Ramakrishnan Date: Tue, 4 Oct 2022 10:23:46 +0200 Subject: [PATCH] support: require superadmin --- CHANGES | 3 +++ src/server.js | 6 +++--- 2 files changed, 6 insertions(+), 3 deletions(-) diff --git a/CHANGES b/CHANGES index 219aa5fd9..157a4f76d 100644 --- a/CHANGES +++ b/CHANGES @@ -2544,3 +2544,6 @@ * app proxy: fixes to https proxying * app links: fix icons +[7.3.2] +* support: require owner permissions + diff --git a/src/server.js b/src/server.js index 371218c9c..0c413a070 100644 --- a/src/server.js +++ b/src/server.js @@ -328,9 +328,9 @@ function initializeExpressSync() { router.del ('/api/v1/mail/:domain/lists/:name', token, authorizeMailManager, routes.mail.delList); // support routes - router.post('/api/v1/support/ticket', json, token, authorizeAdmin, routes.support.canCreateTicket, routes.support.createTicket); - router.get ('/api/v1/support/remote_support', token, authorizeAdmin, routes.support.getRemoteSupport); - router.post('/api/v1/support/remote_support', json, token, authorizeAdmin, routes.support.canEnableRemoteSupport, routes.support.enableRemoteSupport); + router.post('/api/v1/support/ticket', json, token, authorizeOwner, routes.support.canCreateTicket, routes.support.createTicket); + router.get ('/api/v1/support/remote_support', token, authorizeOwner, routes.support.getRemoteSupport); + router.post('/api/v1/support/remote_support', json, token, authorizeOwner, routes.support.canEnableRemoteSupport, routes.support.enableRemoteSupport); // domain routes router.post('/api/v1/domains', json, token, authorizeAdmin, routes.domains.add);