From a7d78378165eea258167171b6859561e6cb86cc7 Mon Sep 17 00:00:00 2001 From: "D. Berge" Date: Thu, 14 Sep 2023 13:19:16 +0200 Subject: [PATCH] Allow only admins to patch project configurations --- lib/www/server/api/index.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/www/server/api/index.js b/lib/www/server/api/index.js index a67567f..d25c6fa 100644 --- a/lib/www/server/api/index.js +++ b/lib/www/server/api/index.js @@ -100,8 +100,8 @@ app.map({ get: [ mw.project.summary.get ], }, '/project/:project/configuration': { - patch: [ mw.auth.access.write, mw.project.configuration.patch ], // Modify project configuration get: [ mw.project.configuration.get ], // Get project configuration + patch: [ mw.auth.access.admin, mw.project.configuration.patch ], // Modify project configuration }, /*