Fix files service auth (#71)

This commit is contained in:
Janos Dobronszki
2021-02-22 09:49:35 +00:00
committed by GitHub
parent e677c40840
commit a453566c26

View File

@@ -46,7 +46,8 @@ func (e *Files) Save(ctx context.Context, req *files.SaveRequest, rsp *files.Sav
if err != nil && err != model.ErrorNotFound {
return err
}
if f.Owner != acc.ID {
// if file exists check ownership
if f.Id != "" && f.Owner != acc.ID {
return errors.New("Not authorized")
}
err = e.db.Create(file)