fix(api): allow server owner to delete other admin accounts

This commit is contained in:
sct
2021-04-13 13:09:06 +09:00
parent 2a869f74eb
commit 2ac6fe7f6d

View File

@@ -281,7 +281,7 @@ router.delete<{ id: string }>(
}); });
} }
if (user.hasPermission(Permission.ADMIN)) { if (user.hasPermission(Permission.ADMIN) && req.user?.id !== 1) {
return next({ return next({
status: 405, status: 405,
message: 'You cannot delete users with administrative privileges.', message: 'You cannot delete users with administrative privileges.',