feat: restrict access to inactive user profiles and update deactivation error messages
This commit is contained in:
@@ -130,6 +130,7 @@ export class AgentsService {
|
||||
id: true,
|
||||
email: true,
|
||||
avatar: true,
|
||||
status: true,
|
||||
privacyPreferences: true,
|
||||
},
|
||||
},
|
||||
@@ -141,6 +142,11 @@ export class AgentsService {
|
||||
throw new NotFoundException('Agent profile not found');
|
||||
}
|
||||
|
||||
// Block access to inactive user profiles (unless viewing own profile)
|
||||
if (profile.user.status !== 'ACTIVE' && profile.userId !== requestingUserId) {
|
||||
throw new NotFoundException('Agent profile not found');
|
||||
}
|
||||
|
||||
const visibility = this.getProfileVisibility(profile.user.privacyPreferences);
|
||||
|
||||
// Own profile — always visible
|
||||
@@ -299,9 +305,10 @@ export class AgentsService {
|
||||
|
||||
const skip = (page - 1) * limit;
|
||||
|
||||
// Build where clause — only show admin-approved profiles in search
|
||||
// Build where clause — only show active, admin-approved profiles in search
|
||||
const where: Prisma.AgentProfileWhereInput = {
|
||||
verificationStatus: 'APPROVED',
|
||||
user: { status: 'ACTIVE' },
|
||||
};
|
||||
|
||||
if (search) {
|
||||
|
||||
Reference in New Issue
Block a user