Lock down contoller methods for extra fields.

This commit is contained in:
DESKTOP-T0O5CDB\DESK-555BD
2024-02-13 16:48:24 -07:00
parent ac1c2ca7fe
commit 8584d2cf9c

View File

@@ -99,6 +99,7 @@ namespace CarCareTracker.Controllers
{
return View();
}
[Authorize(Roles = nameof(UserData.IsRootUser))]
public IActionResult GetExtraFieldsModal(int importMode = 0)
{
var recordExtraFields = _extraFieldDataAccess.GetExtraFieldsById(importMode);
@@ -108,6 +109,7 @@ namespace CarCareTracker.Controllers
}
return PartialView("_ExtraFields", recordExtraFields);
}
[Authorize(Roles = nameof(UserData.IsRootUser))]
public IActionResult UpdateExtraFields(RecordExtraField record)
{
try