fixed permissions

This commit is contained in:
Denis Duliçi
2021-01-29 21:38:10 +03:00
parent 62f1f4ce42
commit 26451e0ba8
2 changed files with 35 additions and 6 deletions

View File

@ -38,7 +38,7 @@ class Companies extends ApiController
{
try {
// Check if user can access company
$this->owner($company);
$this->canAccess($company);
return $this->response->item($company, new Transformer());
} catch (\Exception $e) {
@ -135,9 +135,9 @@ class Companies extends ApiController
*
* @return \Dingo\Api\Http\Response
*/
public function owner(Company $company)
public function canAccess($company)
{
if ($this->isUserCompany($company->id)) {
if (!empty($company) && $this->isUserCompany($company->id)) {
return new Response('');
}