From a35df88805410f2028cc9a0235f502d56ee8b87b Mon Sep 17 00:00:00 2001 From: Robert Lebedeu Date: Tue, 17 Dec 2019 12:15:41 +0100 Subject: Allow checklist creation for board members - Only for members with checklist add permission --- models/checklists.js | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) (limited to 'models/checklists.js') diff --git a/models/checklists.js b/models/checklists.js index 3b50cda6..11aba71b 100644 --- a/models/checklists.js +++ b/models/checklists.js @@ -283,8 +283,15 @@ if (Meteor.isServer) { 'POST', '/api/boards/:boardId/cards/:cardId/checklists', function(req, res) { - Authentication.checkUserId(req.userId); - + // Check user is logged in + Authentication.checkLoggedIn(req.userId); + const paramBoardId = req.params.boardId; + // Check user has permission to add checklist to the card + const board = Boards.findOne({ + _id: paramBoardId + }); + const addPermission = allowIsBoardMemberCommentOnly(req.userId, board); + Authentication.checkAdminOrCondition(req.userId, addPermission); const paramCardId = req.params.cardId; const id = Checklists.insert({ title: req.body.title, -- cgit v1.2.3-1-g7c22 From 2bf004120d5a43cd3c3c060fc7c0c30d1b01f220 Mon Sep 17 00:00:00 2001 From: Lauri Ojansivu Date: Fri, 3 Jan 2020 06:49:35 +0200 Subject: Add Worker role. Add more Font Awesome icons. Fix browser console errors when editing user profile name etc. Thanks to xet7 ! Closes #2788 --- models/checklists.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'models/checklists.js') diff --git a/models/checklists.js b/models/checklists.js index 11aba71b..cf73e500 100644 --- a/models/checklists.js +++ b/models/checklists.js @@ -288,7 +288,7 @@ if (Meteor.isServer) { const paramBoardId = req.params.boardId; // Check user has permission to add checklist to the card const board = Boards.findOne({ - _id: paramBoardId + _id: paramBoardId, }); const addPermission = allowIsBoardMemberCommentOnly(req.userId, board); Authentication.checkAdminOrCondition(req.userId, addPermission); -- cgit v1.2.3-1-g7c22