diff --git a/app/Http/Controllers/Api/AssetsController.php b/app/Http/Controllers/Api/AssetsController.php index f7f6da4090..b400a04e2d 100644 --- a/app/Http/Controllers/Api/AssetsController.php +++ b/app/Http/Controllers/Api/AssetsController.php @@ -373,7 +373,10 @@ class AssetsController extends Controller */ public function destroy($id) { + $this->authorize('delete', Asset::class); + if ($asset = Asset::find($id)) { + $this->authorize('delete', $asset); DB::table('assets')