Only logged-in edits (plus record user with edit)

This commit is contained in:
Tom Russell 2018-09-30 22:30:00 +01:00
parent cf2ffd3cc8
commit a9b3a394de

View File

@ -188,9 +188,14 @@ server.route('/building/:building_id.json')
})
})
.post(function (req, res) {
if (!req.session.user_id) {
res.send({error: 'Must be logged in'});
return
}
const user_id = req.session.user_id;
const { building_id } = req.params;
const building = req.body;
saveBuilding(building_id, building).then(building => {
saveBuilding(building_id, building, user_id).then(building => {
if (building.error) {
res.send(building)
return