fix(checkout): use existing admin permission for shipping methods endpoints
This commit is contained in:
@@ -19,7 +19,7 @@ import { UpdateShippingMethodDto } from './dto/update-shipping-method.dto';
|
|||||||
@ApiBearerAuth()
|
@ApiBearerAuth()
|
||||||
@UseGuards(JwtAuthGuard, RolesGuard, PermissionsGuard)
|
@UseGuards(JwtAuthGuard, RolesGuard, PermissionsGuard)
|
||||||
@Roles(UserRole.ADMIN)
|
@Roles(UserRole.ADMIN)
|
||||||
@Permissions('orders.manage')
|
@Permissions('products.manage')
|
||||||
@Controller('admin/checkout')
|
@Controller('admin/checkout')
|
||||||
export class AdminCheckoutController {
|
export class AdminCheckoutController {
|
||||||
constructor(private readonly checkoutService: CheckoutService) {}
|
constructor(private readonly checkoutService: CheckoutService) {}
|
||||||
|
|||||||
Reference in New Issue
Block a user