Skip to content

Commit 2c1b332

Browse files
committed
Minor API handling fixes.
1 parent db168e3 commit 2c1b332

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

app/Policies/APIKeyPolicy.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ class APIKeyPolicy
4343
protected function checkPermission(User $user, Key $key, $permission)
4444
{
4545
// Non-administrative users cannot use administrative routes.
46-
if (! starts_with('user.') && ! $user->isRootAdmin()) {
46+
if (! starts_with($key, 'user.') && ! $user->isRootAdmin()) {
4747
return false;
4848
}
4949

app/Repositories/APIRepository.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -147,7 +147,7 @@ public function create(array $data)
147147
if ($this->user->isRootAdmin() && isset($data['admin_permissions'])) {
148148
unset($pNodes['_user']);
149149

150-
foreach ($data['admin_permissions'] as $permNode) {
150+
foreach ($data['admin_permissions'] as $permission) {
151151
$parts = explode('-', $permission);
152152

153153
if (count($parts) !== 2) {

0 commit comments

Comments
 (0)