mirror of
https://github.com/snipe/snipe-it.git
synced 2026-02-06 09:55:40 +00:00
Added gate to check that the user is allowed to view API keys
Signed-off-by: snipe <snipe@snipe.net>
This commit is contained in:
@ -113,6 +113,12 @@ class ProfileController extends Controller
|
||||
*/
|
||||
public function api()
|
||||
{
|
||||
|
||||
// Make sure the self.api permission has been granted
|
||||
if (!Gate::allows('self.api')) {
|
||||
abort(403);
|
||||
}
|
||||
|
||||
return view('account/api');
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user