From 22635ea05dab85a71fa93dbb98f93da7670ef899 Mon Sep 17 00:00:00 2001 From: Wes Bos Date: Fri, 25 May 2018 14:06:53 -0400 Subject: Delete and Add refetch refinements --- backend/src/resolvers/Mutation.js | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) (limited to 'backend/src/resolvers') diff --git a/backend/src/resolvers/Mutation.js b/backend/src/resolvers/Mutation.js index 9510cd6..2a67da5 100644 --- a/backend/src/resolvers/Mutation.js +++ b/backend/src/resolvers/Mutation.js @@ -81,12 +81,17 @@ const mutations = { }; // 1. find the item const item = await ctx.db.query.item({ where }, `{ user {id}, title, id, description }`); - // 2. Make sure they own it, or are an admin - if (item.user.id !== ctx.request.user.id || !ctx.request.user.permissions.includes('ADMIN')) { + console.log(item.user); + console.log('-----------------'); + console.log(ctx.request.user); + // 2. if they 1. Don't own it AND 2. aren't an admin + if (item.user.id !== ctx.request.user.id && !ctx.request.user.permissions.includes('ADMIN')) { throw new Error("You aren't allowed to delete that item!"); } - // You Should Either Own this item, or have ITEMDELETE in roles + // 3. remove any orderItems this item is in + + return ctx.db.mutation.deleteItem({ where }, info); }, -- cgit v1.3