Skip to content

Commit b0df965

Browse files
committed
minor dbauthz changes
1 parent 7b118ac commit b0df965

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

coderd/database/dbauthz/dbauthz.go

+2-2
Original file line numberDiff line numberDiff line change
@@ -826,7 +826,7 @@ func (q *querier) DeleteOAuth2ProviderAppCodeByID(ctx context.Context, id uuid.U
826826
if err != nil {
827827
return err
828828
}
829-
if err := q.authorizeContext(ctx, rbac.ActionDelete, rbac.ResourceOAuth2ProviderAppCodeToken.WithOwner(code.UserID.String())); err != nil {
829+
if err := q.authorizeContext(ctx, rbac.ActionDelete, code); err != nil {
830830
return err
831831
}
832832
return q.db.DeleteOAuth2ProviderAppCodeByID(ctx, id)
@@ -1222,7 +1222,7 @@ func (q *querier) GetOAuth2ProviderApps(ctx context.Context) ([]database.OAuth2P
12221222
}
12231223

12241224
func (q *querier) GetOAuth2ProviderAppsByUserID(ctx context.Context, userID uuid.UUID) ([]database.GetOAuth2ProviderAppsByUserIDRow, error) {
1225-
// These two authz checks make sure the caller can read all their own tokens.
1225+
// This authz check is to make sure the caller can read all their own tokens.
12261226
if err := q.authorizeContext(ctx, rbac.ActionRead,
12271227
rbac.ResourceOAuth2ProviderAppCodeToken.WithOwner(userID.String())); err != nil {
12281228
return []database.GetOAuth2ProviderAppsByUserIDRow{}, err

0 commit comments

Comments
 (0)