middleware should allow, not deny
This commit is contained in:
@@ -17,7 +17,7 @@ class DeployController extends Controller
|
||||
private function removeSensitiveData($deployment)
|
||||
{
|
||||
$token = auth()->user()->currentAccessToken();
|
||||
if ($token->can('view:sensitive')) {
|
||||
if ($token->can('read:sensitive')) {
|
||||
return serializeApiResponse($deployment);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user