浏览代码

Modified access to GET /api/boards/:boardId/lists/:listId

mayjs 8 年之前
父节点
当前提交
cb99fc582e
共有 1 个文件被更改,包括 1 次插入1 次删除
  1. 1 1
      models/lists.js

+ 1 - 1
models/lists.js

@@ -147,9 +147,9 @@ if (Meteor.isServer) {
   });
 
   JsonRoutes.add('GET', '/api/boards/:boardId/lists/:listId', function (req, res, next) {
-    Authentication.checkUserId( req.userId);
     const paramBoardId = req.params.boardId;
     const paramListId = req.params.listId;
+    Authentication.checkBoardAccess( req.userId, paramBoardId);
     JsonRoutes.sendResult(res, {
       code: 200,
       data: Lists.findOne({ _id: paramListId, boardId: paramBoardId, archived: false }),