Skip to content

Commit

Permalink
Use new middleware as discussed in chat.
Browse files Browse the repository at this point in the history
Previousely, any user could update or delete any menu item. Permissions had no effect for api call.
  • Loading branch information
Michael Ruoss committed Feb 22, 2016
1 parent d76be7b commit 22b4a1f
Showing 1 changed file with 12 additions and 2 deletions.
14 changes: 12 additions & 2 deletions Http/apiRoutes.php
Original file line number Diff line number Diff line change
@@ -1,4 +1,14 @@
<?php

$router->post('menuitem/update', ['as' => 'api.menuitem.update', 'uses' => 'MenuItemController@update']);
$router->post('menuitem/delete', ['as' => 'api.menuitem.delete', 'uses' => 'MenuItemController@delete']);
$router->group(['prefix' => '/menuitem'], function () {
post('/update', [
'as' => 'api.menuitem.update',
'uses' => 'MenuItemController@update',
'middleware' => 'can:menu.menuitem.update',
]);
post('/delete', [
'as' => 'api.menuitem.delete',
'uses' => 'MenuItemController@delete',
'middleware' => 'can:menu.menuitem.destroy'
]);
});

0 comments on commit 22b4a1f

Please sign in to comment.