From db91e4fc933aca7cf92b6295d87ea1963f270b09 Mon Sep 17 00:00:00 2001 From: Alexander Petkov Date: Mon, 4 Mar 2024 13:06:31 +0200 Subject: [PATCH] src/bank-transactions: Check for admin privilleges regardless of env when simulating IRIS transactions --- apps/api/src/bank-transactions/bank-transactions.controller.ts | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/apps/api/src/bank-transactions/bank-transactions.controller.ts b/apps/api/src/bank-transactions/bank-transactions.controller.ts index 90525c1a..3355d8e7 100644 --- a/apps/api/src/bank-transactions/bank-transactions.controller.ts +++ b/apps/api/src/bank-transactions/bank-transactions.controller.ts @@ -169,8 +169,7 @@ export class BankTransactionsController { const isDev = appEnv === 'development' || appEnv === 'staging' if (!isDev) throw new ForbiddenException('Endpoint available only for testing enviroments') - if (appEnv === 'staging' && !isAdmin(user)) - throw new ForbiddenException('Must be either an admin or active affiliate') + if (!isAdmin(user)) throw new ForbiddenException('Must be an admin') return await this.bankTransactionsService.simulateIrisTask( irisDto.irisIbanAccountInfo,