From 60a3ef21c1762f17f211558687aa0b8959efcde5 Mon Sep 17 00:00:00 2001 From: Max Beier Date: Fri, 28 Apr 2017 15:36:20 +0200 Subject: [PATCH] =?UTF-8?q?=E2=9D=97=EF=B8=8F=20fix=20permissions=20on=20m?= =?UTF-8?q?ission=20api=20routes=20#33?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- routes/index.js | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/routes/index.js b/routes/index.js index a9b8a13..0e59600 100644 --- a/routes/index.js +++ b/routes/index.js @@ -23,9 +23,9 @@ exports = module.exports = (app) => { app.get('/volunteer/:token', api.volunteers.setToken); app.get('/api/missions', keystone.middleware.api, isAdmin, api.missions.all); - app.post('/api/missions', keystone.middleware.api, api.missions.create); - app.get('/api/missions/:id', keystone.middleware.api, hasToken, api.missions.one); - app.put('/api/missions/:id', keystone.middleware.api, hasToken, api.missions.update); + app.post('/api/missions', keystone.middleware.api, isAdmin, api.missions.create); + app.get('/api/missions/:id', keystone.middleware.api, isAdmin, api.missions.one); + app.put('/api/missions/:id', keystone.middleware.api, isAdmin, api.missions.update); app.get('/api/volunteers', keystone.middleware.api, isAdmin, api.volunteers.all); app.get('/api/volunteer', keystone.middleware.api, hasToken, api.volunteers.one);