Skip to content

Commit db2075f

Browse files
committed
fix: broken access control
1 parent edf4eb1 commit db2075f

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

controllers/accountController.js

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,7 @@ const postLogin = [
6161
function getAdminView(req, res) {
6262
console.log(req.query.admin === "true");
6363
if (req.query.admin === "true") {
64+
// if (req.user && req.user.is_admin) {
6465
res.render("adminPanel", { title: "admin panel" });
6566
} else {
6667
res.send("this page is for administrators only");

0 commit comments

Comments
 (0)