From 0d092b977f2345818e609eae4aa338ebfd4078ac Mon Sep 17 00:00:00 2001 From: Ali BARIN Date: Fri, 23 Jun 2023 20:34:19 +0000 Subject: [PATCH] feat(authorization): add read flow checks --- packages/backend/src/graphql/queries/get-flow.ts | 2 ++ 1 file changed, 2 insertions(+) diff --git a/packages/backend/src/graphql/queries/get-flow.ts b/packages/backend/src/graphql/queries/get-flow.ts index b7d39852..6d767118 100644 --- a/packages/backend/src/graphql/queries/get-flow.ts +++ b/packages/backend/src/graphql/queries/get-flow.ts @@ -5,6 +5,8 @@ type Params = { }; const getFlow = async (_parent: unknown, params: Params, context: Context) => { + context.currentUser.can('read', 'Flow'); + const flow = await context.currentUser .$relatedQuery('flows') .withGraphJoined('[steps.[connection]]')