Populate only role relation to authorize user

This commit is contained in:
Victor LAMBERT 2019-11-16 01:05:21 +01:00
parent c603ec3499
commit cff8fd9041

View File

@ -16,11 +16,11 @@ module.exports = async (ctx, next) => {
if (isAdmin) { if (isAdmin) {
ctx.state.admin = await strapi ctx.state.admin = await strapi
.query('administrator', 'admin') .query('administrator', 'admin')
.findOne({ id }); .findOne({ id }, ['role']);
} else { } else {
ctx.state.user = await strapi ctx.state.user = await strapi
.query('user', 'users-permissions') .query('user', 'users-permissions')
.findOne({ id }); .findOne({ id }, ['role']);
} }
} catch (err) { } catch (err) {
return handleErrors(ctx, err, 'unauthorized'); return handleErrors(ctx, err, 'unauthorized');