diff --git a/packages/backend/src/helpers/authorization.js b/packages/backend/src/helpers/authorization.js index b8d40136f5..8c20c4f475 100644 --- a/packages/backend/src/helpers/authorization.js +++ b/packages/backend/src/helpers/authorization.js @@ -1,16 +1,17 @@ const authorizationList = { - '/api/v1/users/:userId': { + 'GET /api/v1/users/:userId': { action: 'read', subject: 'User', }, - '/api/v1/users/': { + 'GET /api/v1/users/': { action: 'read', subject: 'User', }, }; export const authorizeUser = async (request, response, next) => { - const currentRoute = request.baseUrl + request.route.path; + const currentRoute = + request.method + ' ' + request.baseUrl + request.route.path; const currentRouteRule = authorizationList[currentRoute]; try {