Skip to content

Commit 5916f55

Browse files
Emyrkcode-asher
authored andcommitted
minor dbauthz changes
1 parent 73552bc commit 5916f55

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

coderd/database/dbauthz/dbauthz.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -806,7 +806,7 @@ func (q *querier) DeleteOAuth2ProviderAppCodeByID(ctx context.Context, id uuid.U
806806
if err != nil {
807807
return err
808808
}
809-
if err := q.authorizeContext(ctx, rbac.ActionDelete, rbac.ResourceOAuth2ProviderAppCodeToken.WithOwner(code.UserID.String())); err != nil {
809+
if err := q.authorizeContext(ctx, rbac.ActionDelete, code); err != nil {
810810
return err
811811
}
812812
return q.db.DeleteOAuth2ProviderAppCodeByID(ctx, id)
@@ -1236,7 +1236,7 @@ func (q *querier) GetOAuth2ProviderApps(ctx context.Context) ([]database.OAuth2P
12361236
}
12371237

12381238
func (q *querier) GetOAuth2ProviderAppsByUserID(ctx context.Context, userID uuid.UUID) ([]database.GetOAuth2ProviderAppsByUserIDRow, error) {
1239-
// These two authz checks make sure the caller can read all their own tokens.
1239+
// This authz check is to make sure the caller can read all their own tokens.
12401240
if err := q.authorizeContext(ctx, rbac.ActionRead,
12411241
rbac.ResourceOAuth2ProviderAppCodeToken.WithOwner(userID.String())); err != nil {
12421242
return []database.GetOAuth2ProviderAppsByUserIDRow{}, err

0 commit comments

Comments
 (0)