[Users | Trunk]: Remove coPersonId from managers if user is not authorized

This commit is contained in:
Konstantinos Triantafyllou 2021-09-09 12:13:23 +00:00
parent 9c9d93dbfc
commit 3a1fb421c3
1 changed files with 5 additions and 3 deletions

View File

@ -22,9 +22,7 @@ import javax.mail.MessagingException;
import javax.ws.rs.*;
import javax.ws.rs.core.MediaType;
import javax.ws.rs.core.Response;
import java.util.Collection;
import java.util.HashSet;
import java.util.List;
import java.util.*;
@Component(value = "RegistryService")
@Path("/registry")
@ -543,6 +541,10 @@ public class RegistryService {
JsonArray emails = calls.getUserEmailByCouId(couId, true);
JsonArray names = calls.getUserNamesByCouId(couId, true);
JsonUtils.mergeUserInfo(managers, emails, names, gson);
} else {
managers.forEach(user -> {
user.getAsJsonObject().remove("coPersonId");
});
}
return Response.status(HttpStatus.OK.value()).entity(jsonUtils.createResponse(managers).toString()).type(MediaType.APPLICATION_JSON).build();
} else {