diff --git a/src/app/history/controllers/HistoryController.php b/src/app/history/controllers/HistoryController.php index 4414027db88de24a187b89258a0af785a33ffe17..50a5207be176b68f52f27130125d40ab5c45bc80 100755 --- a/src/app/history/controllers/HistoryController.php +++ b/src/app/history/controllers/HistoryController.php @@ -60,9 +60,9 @@ class HistoryController public function get(Request $request, Response $response) { -// if (!PrivilegeController::hasPrivilege(['userId' => $GLOBALS['id'], 'privilege' => 'manage_history'])) { -// return $response->withStatus(403)->withJson(['errors' => 'Service forbidden']); -// } + if (!PrivilegeController::hasPrivilege(['userId' => $GLOBALS['id'], 'privilege' => 'manage_history'])) { + return $response->withStatus(403)->withJson(['errors' => 'Service forbidden']); + } $queryParams = $request->getQueryParams(); $body = $request->getParsedBody();