diff --git a/lib/api/2fa/webauthn.js b/lib/api/2fa/webauthn.js index be538393..885f0933 100644 --- a/lib/api/2fa/webauthn.js +++ b/lib/api/2fa/webauthn.js @@ -101,9 +101,9 @@ module.exports = (db, server, userHandler) => { // permissions check if (req.user && req.user === result.value.user) { - req.validate(roles.can(req.role).deleteOwn('users')); + req.validate(roles.can(req.role).updateOwn('users')); } else { - req.validate(roles.can(req.role).deleteAny('users')); + req.validate(roles.can(req.role).updateAny('users')); } let user = new ObjectId(result.value.user);