diff --git a/src/middlewares/checkOwnership.js b/src/middlewares/checkOwnership.js index 65a9cde..43b89e8 100644 --- a/src/middlewares/checkOwnership.js +++ b/src/middlewares/checkOwnership.js @@ -1,7 +1,5 @@ export default (req, res, next) => { - const { _id } = req.user; - const { id } = req.params; - if(_id == id) next(); + if(req.user._id.equals(req.params.id)) next(); else res.status(403).json({ success: false, message: 'Access denied. User not permitted.'