diff --git a/src/webapi/router/router.go b/src/webapi/router/router.go index 586053ae..a8c457e7 100644 --- a/src/webapi/router/router.go +++ b/src/webapi/router/router.go @@ -134,7 +134,7 @@ func configRoute(r *gin.Engine, version string) { pages.PUT("/user/:id/password", jwtAuth(), admin(), userPasswordPut) pages.DELETE("/user/:id", jwtAuth(), admin(), userDel) - pages.GET("/user-groups", jwtAuth(), user(), userGroupGets) + pages.GET("/user-groups", jwtAuth(), user(), perm("/user-groups"), userGroupGets) pages.POST("/user-groups", jwtAuth(), user(), userGroupAdd) pages.GET("/user-group/:id", jwtAuth(), user(), userGroupGet) pages.PUT("/user-group/:id", jwtAuth(), user(), userGroupWrite(), userGroupPut) @@ -143,7 +143,7 @@ func configRoute(r *gin.Engine, version string) { pages.DELETE("/user-group/:id/members", jwtAuth(), user(), userGroupWrite(), userGroupMemberDel) pages.GET("/user-group/:id/perm/:perm", jwtAuth(), user(), checkBusiGroupPerm) - pages.POST("/busi-groups", jwtAuth(), user(), busiGroupAdd) + pages.POST("/busi-groups", jwtAuth(), user(), perm("/busi-groups"), busiGroupAdd) pages.GET("/busi-groups", jwtAuth(), user(), busiGroupGets) pages.GET("/busi-groups/alertings", jwtAuth(), busiGroupAlertingsGets) pages.GET("/busi-group/:id", jwtAuth(), user(), bgro(), busiGroupGet)