Skip to content

Add permission check when user update VodcfsSession #32

@danny900714

Description

@danny900714

Currently, casl allow all update action to VodcfsSession. However, updating VodcfsSeesion of different user than actor is an unwilling operation for default USER role. Hence, we should find a way to validate full domain object in PoliciesGuard.

Metadata

Metadata

Assignees

No one assigned

    Labels

    backendThe backend providing GraphQL APIbug 🐛Something isn't workingdomain: vodcfs sessionThe domain resource

    Type

    No type

    Projects

    Status

    Todo

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions