From daf3f47b4ea1cd8ed2786be29a3d2cc59847ce32 Mon Sep 17 00:00:00 2001 From: mingrammer <mingrammer@gmail.com> Date: Sun, 8 Dec 2024 23:25:18 +0900 Subject: [PATCH] fix: case the id to int --- webapp/backend/apiserver/controllers/userController.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/webapp/backend/apiserver/controllers/userController.js b/webapp/backend/apiserver/controllers/userController.js index c8ea91f..54da91b 100644 --- a/webapp/backend/apiserver/controllers/userController.js +++ b/webapp/backend/apiserver/controllers/userController.js @@ -218,7 +218,7 @@ exports.updateUser = async (req, res) => { const userID = req.user.userID; - if (req.params.id !== userID) { + if (parseInt(req.params.id) !== parseInt(userID)) { return res.status(403).json({ error: '사용자 정보를 업데이트할 권한이 없습니다.' }); @@ -279,7 +279,7 @@ exports.updateUser = async (req, res) => { exports.deleteUser = async (req, res) => { const userID = req.user.userID; - if (req.params.id !== userID) { + if (parseInt(req.params.id) !== parseInt(userID)) { return res.status(403).json({ error: '사용자 정보를 삭제할 권한이 없습니다.' }); -- GitLab