fix(api): allow server owner to delete other admin accounts

This commit is contained in:
sct
2021-04-13 13:09:06 +09:00
parent 2a869f74eb
commit 2ac6fe7f6d

View File

@@ -281,7 +281,7 @@ router.delete<{ id: string }>(
});
}
if (user.hasPermission(Permission.ADMIN)) {
if (user.hasPermission(Permission.ADMIN) && req.user?.id !== 1) {
return next({
status: 405,
message: 'You cannot delete users with administrative privileges.',