Commit c9e25b66 authored by Sang D NGO's avatar Sang D NGO

only admin can view all proposal

parent 37b37b76
......@@ -37,7 +37,7 @@ module.exports = function(dependencies, lib) {
function getProposals(req, res) {
var listOptions = {
creator: req.user.id,
creator: req.query.creator,
type: req.query.type,
status: req.query.status,
limit: Number(req.query.limit),
......
......@@ -6,7 +6,10 @@
var API_PATH = 'proposals';
function mostProposalApiClient(mostRestangular) {
function mostProposalApiClient(
session,
mostRestangular
) {
return {
createProposal: createProposal,
getProposals: getProposals,
......@@ -19,6 +22,10 @@
}
function getProposals(options) {
if (!session.userIsDomainAdministrator()) {
options.creator = session.user._id;
}
return mostRestangular.all(API_PATH).getList(options).then(_stripAndReturnData).then(function(proposals) {
return proposals.map(_decodeFormData);
});
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment