From f43005de8bac8425cb48a878d1e49b56a9a7e319 Mon Sep 17 00:00:00 2001 From: Mark Moffat Date: Fri, 8 Nov 2019 15:22:31 +1030 Subject: [PATCH] Removed incorrect check editing own owner account --- routes/user.js | 8 -------- 1 file changed, 8 deletions(-) diff --git a/routes/user.js b/routes/user.js index ebe1deb..1486c0f 100644 --- a/routes/user.js +++ b/routes/user.js @@ -41,14 +41,6 @@ router.get('/admin/user/edit/:id', restrict, (req, res) => { return; } - // Cannot edit the original user/owner - if(user._id !== req.session.userId && user.isOwner){ - req.session.message = 'Access denied.'; - req.session.messageType = 'danger'; - res.redirect('/admin/users'); - return; - } - // if the user we want to edit is not the current logged in user and the current user is not // an admin we render an access denied message if(user.userEmail !== req.session.user && req.session.isAdmin === false){