diff --git a/website/api/policies/has-query-generator-access.js b/website/api/policies/has-query-generator-access.js index 572db7db1d..27a84576be 100644 --- a/website/api/policies/has-query-generator-access.js +++ b/website/api/policies/has-query-generator-access.js @@ -23,12 +23,12 @@ module.exports = async function (req, res, proceed) { } }//• - // Check if this user can access the query generator. - if (!req.me.canUseQueryGenerator) { - return res.forbidden(); - // Then check that this user is a "super admin". - } else if (!req.me.canUseQueryGenerator && !req.me.isSuperAdmin) { - return res.forbidden(); + // Check that this user is a "super admin". + if(!req.me.isSuperAdmin) { + // Then check if this user can access the query generator. + if (!req.me.canUseQueryGenerator) { + return res.forbidden(); + } } // IWMIH, this user can access the query generator.