Skip to content

Commit 5e4357c

Browse files
committed
Albums: Refactor permission check in internal/api/albums.go
Signed-off-by: Michael Mayer <[email protected]>
1 parent fa487ed commit 5e4357c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

internal/api/albums.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ func GetAlbum(router *gin.RouterGroup) {
7070
}
7171

7272
// Other restricted users can only access their own or shared content.
73-
if album.CreatedBy != s.UserUID && s.User().HasSharedAccessOnly(acl.ResourceAlbums) {
73+
if s.User().HasSharedAccessOnly(acl.ResourceAlbums) && album.CreatedBy != s.UserUID && !s.HasShare(uid) {
7474
AbortForbidden(c)
7575
return
7676
}

0 commit comments

Comments
 (0)