From fee13804d57694bafb1db4f4ed3ee9097c45dcda Mon Sep 17 00:00:00 2001 From: drkthunder02 Date: Thu, 10 Jan 2019 08:50:59 -0600 Subject: [PATCH] adjusted RequireRole middleware to be more cohesivie --- app/Http/Middleware/RequireRole.php | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/app/Http/Middleware/RequireRole.php b/app/Http/Middleware/RequireRole.php index fbea15cf1..0e31b3231 100644 --- a/app/Http/Middleware/RequireRole.php +++ b/app/Http/Middleware/RequireRole.php @@ -33,12 +33,10 @@ class RequireRole abort(403, "You don't any roles. You don't belong here."); } - if($ranking[$check[0]->role] >= $ranking[$role]) { - $confirmed = true; + if($ranking[$check[0]->role] < $ranking[$role]) { + abort(403, "You don't have the correct role to be in this area."); } - abort_unless(auth()->check() && $confirmed, 403, "You don't have the correct role to be in this area."); - return $next($request); } }