mirror of
https://github.com/jellyfin/jellyfin.git
synced 2026-01-15 23:58:57 +00:00
Added access validation to view item user data.
This commit is contained in:
@@ -902,6 +902,11 @@ public class ItemsController : BaseJellyfinApiController
|
||||
[FromRoute, Required] Guid userId,
|
||||
[FromRoute, Required] Guid itemId)
|
||||
{
|
||||
if (!RequestHelpers.AssertCanUpdateUser(_userManager, User, userId, true))
|
||||
{
|
||||
return StatusCode(StatusCodes.Status403Forbidden, "User is not allowed to view this item user data.");
|
||||
}
|
||||
|
||||
var user = _userManager.GetUserById(userId) ?? throw new ResourceNotFoundException();
|
||||
var item = _libraryManager.GetItemById(itemId);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user