fix(note): permissions of purgeNoteRevisions

This should only be allowed to be done by owners.

Signed-off-by: Philip Molares <philip.molares@udo.edu>
This commit is contained in:
Philip Molares 2022-10-03 21:12:53 +02:00
parent 9bf85a671d
commit 50ea4b5877

View file

@ -165,7 +165,7 @@ export class NotesController {
@Delete(':noteIdOrAlias/revisions') @Delete(':noteIdOrAlias/revisions')
@OpenApi(204, 404) @OpenApi(204, 404)
@Permissions(Permission.READ) @Permissions(Permission.OWNER)
@UseInterceptors(GetNoteInterceptor) @UseInterceptors(GetNoteInterceptor)
async purgeNoteRevisions( async purgeNoteRevisions(
@RequestUser() user: User, @RequestUser() user: User,