fix(security): isActive defense-in-depth, MIME magic bytes upload, tenantId=origins OAuth
All checks were successful
CI/CD — Build & Deploy / Build & Deploy (push) Successful in 54s
All checks were successful
CI/CD — Build & Deploy / Build & Deploy (push) Successful in 54s
This commit is contained in:
@@ -64,6 +64,11 @@ export const requireAuth = async (
|
||||
return;
|
||||
}
|
||||
|
||||
if (!data.data.user.isActive) {
|
||||
res.status(401).json({ success: false, error: "ACCOUNT_DISABLED", message: "Account is disabled" });
|
||||
return;
|
||||
}
|
||||
|
||||
(req as AuthenticatedRequest).user = data.data.user;
|
||||
next();
|
||||
} catch (err) {
|
||||
|
||||
Reference in New Issue
Block a user