feat: deny anonymous user from getting orgs

This commit is contained in:
swve 2023-04-24 20:42:25 +02:00
parent 74ccbc5738
commit 3f2d9d2b9f

View file

@ -149,6 +149,12 @@ async def get_orgs_by_user(request: Request, user_id: str, page: int = 1, limit:
orgs = request.app.db["organizations"]
user = request.app.db["users"]
if user_id is "anonymous":
# raise error
raise HTTPException(
status_code=status.HTTP_409_CONFLICT, detail="User not logged in")
# get user orgs
user_orgs = await user.find_one({"user_id": user_id})