protect apis
This commit is contained in:
@@ -83,6 +83,10 @@ class LoanOrderController extends Controller
|
|||||||
*/
|
*/
|
||||||
public function show(LoanOrder $loanOrder)
|
public function show(LoanOrder $loanOrder)
|
||||||
{
|
{
|
||||||
|
if ($loanOrder->user_id === auth()->id()) {
|
||||||
|
return response()->status(403);
|
||||||
|
}
|
||||||
|
|
||||||
return response()->json(new LoanOrderShowResource($loanOrder));
|
return response()->json(new LoanOrderShowResource($loanOrder));
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -99,6 +103,10 @@ class LoanOrderController extends Controller
|
|||||||
*/
|
*/
|
||||||
public function destroy(LoanOrder $loanOrder): void
|
public function destroy(LoanOrder $loanOrder): void
|
||||||
{
|
{
|
||||||
|
if ($loanOrder->user_id === auth()->id()) {
|
||||||
|
return response()->status(403);
|
||||||
|
}
|
||||||
|
|
||||||
$loanOrder->delete();
|
$loanOrder->delete();
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user