diff --git a/functions/api/events-team/points/_middleware.ts b/functions/api/events-team/points/_middleware.ts new file mode 100644 index 0000000..9c61388 --- /dev/null +++ b/functions/api/events-team/points/_middleware.ts @@ -0,0 +1,12 @@ +import { jsonError } from "../../../common.js"; + +export async function onRequest(context: RequestContext) { + const { current_user: user } = context.data; + + if (!user) return jsonError("You are not logged in", 401); + + if (![1 << 3, 1 << 4, 1 << 2].find((p) => user.permissions & p)) + return jsonError("Not part of Events Team", 403); + + return await context.next(); +}