Skip to content

Commit

Permalink
chore: amend users query with user scopes
Browse files Browse the repository at this point in the history
  • Loading branch information
Nil20 committed Nov 6, 2024
1 parent 88e0130 commit 06cd94c
Showing 1 changed file with 3 additions and 5 deletions.
8 changes: 3 additions & 5 deletions packages/gateway/src/features/user/root-resolvers.ts
Original file line number Diff line number Diff line change
Expand Up @@ -87,8 +87,7 @@ export const resolvers: GQLResolver = {
if (
!inScope(authHeader, [
SCOPES.USER_READ,
SCOPES.RECORD_REGISTER,
SCOPES.RECORD_SUBMIT_FOR_APPROVAL
SCOPES.USER_READ_MY_JURISDICTION
])
) {
return await Promise.reject(
Expand Down Expand Up @@ -150,8 +149,7 @@ export const resolvers: GQLResolver = {
if (
!inScope(authHeader, [
SCOPES.USER_READ,
SCOPES.RECORD_REGISTER,
SCOPES.RECORD_SUBMIT_FOR_APPROVAL
SCOPES.USER_READ_MY_JURISDICTION
])
) {
return await Promise.reject(
Expand Down Expand Up @@ -369,7 +367,7 @@ export const resolvers: GQLResolver = {
) {
// Only token owner of CONFIG_UPDATE_ALL should be able to change their password
if (
!hasScope(authHeader, SCOPES.CONFIG_UPDATE_ALL) &&
!hasScope(authHeader, SCOPES.USER_READ) &&
!isTokenOwner(authHeader, userId)
) {
return await Promise.reject(
Expand Down

0 comments on commit 06cd94c

Please sign in to comment.