From fbe04b31e7346513b3383daa7b7fb525d3ebd000 Mon Sep 17 00:00:00 2001 From: pradeepkumar Date: Tue, 31 Mar 2026 23:42:15 +0530 Subject: [PATCH] feat: restrict access to inactive user profiles and update deactivation error messages --- src/agents/agents.service.ts | 9 ++++++++- src/auth/auth.service.ts | 4 ++-- 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/src/agents/agents.service.ts b/src/agents/agents.service.ts index 8e36ddb..5a32f37 100644 --- a/src/agents/agents.service.ts +++ b/src/agents/agents.service.ts @@ -130,6 +130,7 @@ export class AgentsService { id: true, email: true, avatar: true, + status: true, privacyPreferences: true, }, }, @@ -141,6 +142,11 @@ export class AgentsService { throw new NotFoundException('Agent profile not found'); } + // Block access to inactive user profiles (unless viewing own profile) + if (profile.user.status !== 'ACTIVE' && profile.userId !== requestingUserId) { + throw new NotFoundException('Agent profile not found'); + } + const visibility = this.getProfileVisibility(profile.user.privacyPreferences); // Own profile — always visible @@ -299,9 +305,10 @@ export class AgentsService { const skip = (page - 1) * limit; - // Build where clause — only show admin-approved profiles in search + // Build where clause — only show active, admin-approved profiles in search const where: Prisma.AgentProfileWhereInput = { verificationStatus: 'APPROVED', + user: { status: 'ACTIVE' }, }; if (search) { diff --git a/src/auth/auth.service.ts b/src/auth/auth.service.ts index cf7c415..214db94 100644 --- a/src/auth/auth.service.ts +++ b/src/auth/auth.service.ts @@ -151,7 +151,7 @@ export class AuthService { } if (user.status !== UserStatus.ACTIVE) { - throw new UnauthorizedException('Account is not active'); + throw new UnauthorizedException('Your account has been deactivated. Please contact support.'); } // Check if email is verified @@ -334,7 +334,7 @@ export class AuthService { } if (user.status !== UserStatus.ACTIVE) { - throw new UnauthorizedException('Account is not active'); + throw new UnauthorizedException('Your account has been deactivated. Please contact support.'); } // Generate tokens