fix(auth): 🚑️ Don't allow user without id
This commit is contained in:
@ -8,11 +8,10 @@ import { methodNotAllowed } from 'utils'
|
|||||||
|
|
||||||
const handler = async (req: NextApiRequest, res: NextApiResponse) => {
|
const handler = async (req: NextApiRequest, res: NextApiResponse) => {
|
||||||
const session = await getSession({ req })
|
const session = await getSession({ req })
|
||||||
|
|
||||||
if (!session?.user)
|
if (!session?.user)
|
||||||
return res.status(401).json({ message: 'Not authenticated' })
|
return res.status(401).json({ message: 'Not authenticated' })
|
||||||
|
|
||||||
const user = session.user as User
|
const user = session.user as User
|
||||||
|
if (!user.id) return res.status(401).json({ message: 'Not authenticated' })
|
||||||
try {
|
try {
|
||||||
if (req.method === 'GET') {
|
if (req.method === 'GET') {
|
||||||
const folderId = req.query.folderId ? req.query.folderId.toString() : null
|
const folderId = req.query.folderId ? req.query.folderId.toString() : null
|
||||||
|
Reference in New Issue
Block a user