diff options
| author | Cody Robibero <cody@robibe.ro> | 2024-08-28 12:39:48 -0600 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2024-08-28 12:39:48 -0600 |
| commit | 8c3f3c503b4b0606e2987ed58e5228d72669afeb (patch) | |
| tree | f139dd171ac4fcc5328061aa455644586c428b7a /Jellyfin.Api/Controllers/ImageController.cs | |
| parent | 639d75bd8300ee9538c5a8142cb86b7e89305d9a (diff) | |
| parent | e221c1d25d640eaac01220b3f5b1422f4c11ed46 (diff) | |
Merge pull request #11665 from Bond-009/getuserbyid
Diffstat (limited to 'Jellyfin.Api/Controllers/ImageController.cs')
| -rw-r--r-- | Jellyfin.Api/Controllers/ImageController.cs | 13 |
1 files changed, 9 insertions, 4 deletions
diff --git a/Jellyfin.Api/Controllers/ImageController.cs b/Jellyfin.Api/Controllers/ImageController.cs index 6a169eae3..b71199026 100644 --- a/Jellyfin.Api/Controllers/ImageController.cs +++ b/Jellyfin.Api/Controllers/ImageController.cs @@ -109,7 +109,7 @@ public class ImageController : BaseJellyfinApiController return NotFound(); } - if (!RequestHelpers.AssertCanUpdateUser(_userManager, HttpContext.User, requestUserId, true)) + if (!RequestHelpers.AssertCanUpdateUser(HttpContext.User, user, true)) { return StatusCode(StatusCodes.Status403Forbidden, "User is not allowed to update the image."); } @@ -203,13 +203,18 @@ public class ImageController : BaseJellyfinApiController [FromQuery] Guid? userId) { var requestUserId = RequestHelpers.GetUserId(User, userId); - if (!RequestHelpers.AssertCanUpdateUser(_userManager, HttpContext.User, requestUserId, true)) + var user = _userManager.GetUserById(requestUserId); + if (user is null) + { + return NotFound(); + } + + if (!RequestHelpers.AssertCanUpdateUser(HttpContext.User, user, true)) { return StatusCode(StatusCodes.Status403Forbidden, "User is not allowed to delete the image."); } - var user = _userManager.GetUserById(requestUserId); - if (user?.ProfileImage is null) + if (user.ProfileImage is null) { return NoContent(); } |
