Browse Source

Fixed permission check in OrderAppService

pull/49/head
gdlcf88 6 years ago
parent
commit
73488edd58
  1. 6
      modules/EasyAbp.EShop.Orders/src/EasyAbp.EShop.Orders.Application/EasyAbp/EShop/Orders/Orders/OrderAppService.cs

6
modules/EasyAbp.EShop.Orders/src/EasyAbp.EShop.Orders.Application/EasyAbp/EShop/Orders/Orders/OrderAppService.cs

@ -63,7 +63,7 @@ namespace EasyAbp.EShop.Orders.Orders
{ {
if (input.CustomerUserId != CurrentUser.GetId()) if (input.CustomerUserId != CurrentUser.GetId())
{ {
await AuthorizationService.IsGrantedAsync(OrdersPermissions.Orders.Manage); await AuthorizationService.CheckAsync(OrdersPermissions.Orders.Manage);
if (input.StoreId.HasValue) if (input.StoreId.HasValue)
{ {
@ -71,7 +71,7 @@ namespace EasyAbp.EShop.Orders.Orders
} }
else else
{ {
await AuthorizationService.IsGrantedAsync(OrdersPermissions.Orders.CrossStore); await AuthorizationService.CheckAsync(OrdersPermissions.Orders.CrossStore);
} }
} }
@ -86,7 +86,7 @@ namespace EasyAbp.EShop.Orders.Orders
if (order.CustomerUserId != CurrentUser.GetId()) if (order.CustomerUserId != CurrentUser.GetId())
{ {
await AuthorizationService.IsGrantedAsync(OrdersPermissions.Orders.Manage); await AuthorizationService.CheckAsync(OrdersPermissions.Orders.Manage);
// Todo: Check if current user is an admin of the store. // Todo: Check if current user is an admin of the store.
} }

Loading…
Cancel
Save