diff --git a/lib/app/base-chips/access-strategy-types/owner.js b/lib/app/base-chips/access-strategy-types/owner.js index f723c4d3..dfa36d0a 100644 --- a/lib/app/base-chips/access-strategy-types/owner.js +++ b/lib/app/base-chips/access-strategy-types/owner.js @@ -1,28 +1,28 @@ "use strict"; const Promise = require("bluebird"); const Query = require("../../../datastore/query.js"); module.exports = { name: "owner", getRestrictingQuery: async function(context, params) { if (context.user_id) { return Query.fromSingleMatch({ "created_context.user_id": { $eq: context.user_id }, }); } - return new Query.DenyQuery(); + return new Query.DenyAll(); }, checker_function: function(context, params, item) { if ( context.user_id && context.user_id === item.created_context.user_id ) { return Promise.resolve(); } else { return Promise.reject( "Only the owner of this resource can perform this operation on this item." ); } }, item_sensitive: true, };