diff options
| -rw-r--r-- | src/routes/model.rs | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/routes/model.rs b/src/routes/model.rs index 5fe75a1..7a98c56 100644 --- a/src/routes/model.rs +++ b/src/routes/model.rs @@ -138,7 +138,7 @@ async fn upload_model_file( } }; - if model.author_id() != claims.user_id { + if !(model.author_id() == user.id || user.is_staff.unwrap()) { return Err(AppError::Unauthorized); } |
