aravind changes
This commit is contained in:
@@ -128,6 +128,11 @@ func (s *Server) handleAssign(w http.ResponseWriter, r *http.Request) {
|
||||
ident, ok := s.authorizeAll(w, r,
|
||||
requirement{"assignments", domain.OpCreate},
|
||||
requirement{"job-applications", domain.OpUpdate},
|
||||
// The workflow may now FILE an application as well as patch one, for a
|
||||
// worker placed on a posting they never applied to. A write the handler
|
||||
// performs has to appear in the list it is authorized against, even
|
||||
// when — as here — the resulting permission set is unchanged.
|
||||
requirement{"job-applications", domain.OpCreate},
|
||||
requirement{"user-activity", domain.OpCreate},
|
||||
)
|
||||
if !ok {
|
||||
|
||||
Reference in New Issue
Block a user