Fix the user role checking in History routes

This commit is contained in:
Khanh Ngo
2018-09-04 17:58:13 +07:00
parent c8d72f5bba
commit 67dd626c65
2 changed files with 2 additions and 2 deletions

View File

@@ -1324,7 +1324,7 @@ def admin_manageaccount():
@operator_role_required
def admin_history():
if request.method == 'POST':
if current_user.role != 'Administrator':
if current_user.role.name != 'Administrator':
return make_response(jsonify( { 'status': 'error', 'msg': 'You do not have permission to remove history.' } ), 401)
h = History()