From ac1d09add0bb0f3842f70e1b7df6a6b6b18028c1 Mon Sep 17 00:00:00 2001 From: spencerrlongg Date: Tue, 26 Nov 2024 14:49:50 -0600 Subject: [PATCH] Fix authorization check in AssetsController Removed incorrect and commented-out authorization check in the destroy method. Ensured proper authorization by explicitly authorizing the asset instance before attempting deletion. --- app/Http/Controllers/Api/AssetsController.php | 2 -- 1 file changed, 2 deletions(-) diff --git a/app/Http/Controllers/Api/AssetsController.php b/app/Http/Controllers/Api/AssetsController.php index 264dc26bf7..b73ddff3df 100644 --- a/app/Http/Controllers/Api/AssetsController.php +++ b/app/Http/Controllers/Api/AssetsController.php @@ -673,8 +673,6 @@ class AssetsController extends Controller */ public function destroy(Asset $asset): JsonResponse { - //this is probably wrong - //$this->authorize('delete', Asset::class); $this->authorize('delete', $asset); try { DestroyAssetAction::run($asset);