From b3cd17b9a334a0e75e1b084bbbf9bf1da98f7cf9 Mon Sep 17 00:00:00 2001 From: Michael Shanks Date: Wed, 27 May 2020 19:18:39 +0100 Subject: [PATCH] bugfix: wrong permissions on worfklow endpoint --- packages/server/src/api/routes/workflow.js | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/packages/server/src/api/routes/workflow.js b/packages/server/src/api/routes/workflow.js index a5f78dccf1..38563f0976 100644 --- a/packages/server/src/api/routes/workflow.js +++ b/packages/server/src/api/routes/workflow.js @@ -1,7 +1,7 @@ const Router = require("@koa/router") const controller = require("../controllers/workflow") const authorized = require("../../middleware/authorized") -const { BUILDER } = require("../../utilities/accessLevels") +const { BUILDER, EXECUTE_WORKFLOW } = require("../../utilities/accessLevels") const router = Router() @@ -17,7 +17,7 @@ router .post("/api/:instanceId/workflows", authorized(BUILDER), controller.create) .post( "/api/:instanceId/workflows/action", - authorized(BUILDER), + authorized(EXECUTE_WORKFLOW), controller.executeAction ) .delete(