From ef3d9bb71da71596c1171c3633a83efde25959be Mon Sep 17 00:00:00 2001 From: Dhruv Shah Date: Sat, 3 Feb 2024 13:23:56 +0530 Subject: [PATCH] feat: allow admins to delete accounts --- vitty-backend-api/api/v2/userHandler.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/vitty-backend-api/api/v2/userHandler.go b/vitty-backend-api/api/v2/userHandler.go index 6507b14..2058174 100644 --- a/vitty-backend-api/api/v2/userHandler.go +++ b/vitty-backend-api/api/v2/userHandler.go @@ -71,7 +71,7 @@ func deleteUser(c *fiber.Ctx) error { request_user := c.Locals("user").(models.User) c.Params("username") - if request_user.Username != c.Params("username") { + if request_user.Username != c.Params("username") && request_user.Role != "admin" { return c.Status(fiber.StatusForbidden).JSON(fiber.Map{ "detail": "You are not authorized to delete this user", })