diff --git a/src/app/search/controllers/SearchController.php b/src/app/search/controllers/SearchController.php index 9a6d4878e2c26b245aeaf863185a7eb870ab0eee..b85e65531ce939275b29e5d646976c74e3039625 100755 --- a/src/app/search/controllers/SearchController.php +++ b/src/app/search/controllers/SearchController.php @@ -36,7 +36,7 @@ class SearchController $queryParams['softDeleted'] = empty($queryParams['softDeleted']) ? false : $queryParams['softDeleted'] == 'true'; $queryParams['hardDeleted'] = empty($queryParams['hardDeleted']) ? false : $queryParams['hardDeleted'] == 'true'; - if ($queryParams['softDeleted'] && !PrivilegeController::hasPrivilege(['userId' => $GLOBALS['id'], 'privilege' => 'can_purge'])) { + if (($queryParams['softDeleted'] || $queryParams['softDeleted']) && !PrivilegeController::hasPrivilege(['userId' => $GLOBALS['id'], 'privilege' => 'can_purge'])) { return $response->withStatus(403)->withJson(['errors' => 'Privilege forbidden']); }