+1
-1
@@ -30,7 +30,7 @@ app.use('/api/uploads', express.static(UPLOAD_PATH));
|
||||
app.use('/api/projects', requireAuth, projectsRouter);
|
||||
app.use('/api/tools', requireAuth, toolsRouter);
|
||||
app.use('/api/uploads', requireAuth, uploadsRouter); // handles POST + DELETE only
|
||||
app.use('/api/settings', requireAuth, settingsRouter);
|
||||
app.use('/api/settings', settingsRouter); // GET is public (branding on login page); PUT/POST require admin (per-method in router)
|
||||
app.use('/api/users', usersRouter); // requireAdmin applied inside router
|
||||
|
||||
// Serve built React client in production
|
||||
|
||||
Reference in New Issue
Block a user