1 files changed, 2 insertions, 1 deletions
diff --git a/api/src/routes/users/@me/settings.ts b/api/src/routes/users/@me/settings.ts
index 5664fc2f..f045a010 100644
--- a/api/src/routes/users/@me/settings.ts
+++ b/api/src/routes/users/@me/settings.ts
@@ -8,7 +8,8 @@ const router = Router();
router.patch("/", check(UserSettingsSchema), async (req: Request, res: Response) => {
const body = req.body as UserSettings;
- await UserModel.updateOne({ id: req.user_id }, body).exec();
+ // only users can update user settings
+ await UserModel.updateOne({ id: req.user_id, bot: false }, body).exec();
res.sendStatus(204);
});
|