This commit is contained in:
David Bomba 2022-06-16 15:59:36 +10:00
parent 77d0dd8ae4
commit ce1aea5146

View File

@ -26,7 +26,7 @@ class UpdateAccountRequest extends Request
*/ */
public function authorize() public function authorize()
{ {
return auth()->user()->isAdmin() || auth()->user()->isOwner(); return (auth()->user()->isAdmin() || auth()->user()->isOwner()) && (int)$this->account->id === auth()->user()->account_id;
} }
/** /**
@ -41,6 +41,7 @@ class UpdateAccountRequest extends Request
]; ];
} }
/* Only allow single field to update account table */
protected function prepareForValidation() protected function prepareForValidation()
{ {
$input = $this->all(); $input = $this->all();