Added access validation to view item user data.

pull/10573/head
ArabCoders 7 months ago
parent 2a25c5a2e3
commit faa036aa7b

@ -902,6 +902,11 @@ public class ItemsController : BaseJellyfinApiController
[FromRoute, Required] Guid userId,
[FromRoute, Required] Guid itemId)
{
if (!RequestHelpers.AssertCanUpdateUser(_userManager, User, userId, true))
{
return StatusCode(StatusCodes.Status403Forbidden, "User is not allowed to view this item user data.");
}
var user = _userManager.GetUserById(userId) ?? throw new ResourceNotFoundException();
var item = _libraryManager.GetItemById(itemId);

Loading…
Cancel
Save