From 68055712d999c5216b5591cca345b8ca63d6340c Mon Sep 17 00:00:00 2001 From: Pierre HUBERT Date: Thu, 17 Mar 2022 18:08:03 +0100 Subject: [PATCH] Fix incorrect access control check to delete posts --- src/controllers/posts_controller.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/controllers/posts_controller.rs b/src/controllers/posts_controller.rs index c2a5104..9ab852d 100644 --- a/src/controllers/posts_controller.rs +++ b/src/controllers/posts_controller.rs @@ -270,7 +270,7 @@ pub async fn update_content(r: &mut HttpRequestHandler) -> RequestResult { /// Delete a post pub async fn delete(r: &mut HttpRequestHandler) -> RequestResult { - let post = r.post_post_with_access("postID", PostAccessLevel::FULL_ACCESS)?; + let post = r.post_post_with_access("postID", PostAccessLevel::INTERMEDIATE_ACCESS)?; posts_helper::delete(&post).await?;