Przeglądaj źródła

permitted for admin user only

Shun Miyazawa 3 lat temu
rodzic
commit
a626df65ec
1 zmienionych plików z 1 dodań i 1 usunięć
  1. 1 1
      packages/app/src/server/routes/apiv3/users.js

+ 1 - 1
packages/app/src/server/routes/apiv3/users.js

@@ -967,7 +967,7 @@ module.exports = (crowi) => {
         Object.assign(data, { inactiveUsernames });
         Object.assign(data, { inactiveUsernames });
       }
       }
 
 
-      if (stringToBoolean(req.query.isIncludeActivitySnapshotUsernames)) {
+      if (stringToBoolean(req.query.isIncludeActivitySnapshotUsernames) && req.user.admin) {
         const userActivies = await Activity.find({
         const userActivies = await Activity.find({
           'snapshot.username': { $regex: q, $options: 'i' },
           'snapshot.username': { $regex: q, $options: 'i' },
         });
         });