diff --git a/server/pkg/service/middleware.go b/server/pkg/service/middleware.go index 35fd2ee..b730a8b 100644 --- a/server/pkg/service/middleware.go +++ b/server/pkg/service/middleware.go @@ -78,7 +78,7 @@ func ownerOnlyMiddleware(next http.Handler) http.Handler { return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { user, ok := r.Context().Value(userCtxKey{}).(*userClaims) requestedID := chi.URLParam(r, "id") - if !ok || user.ID != requestedID { + if !ok || user.Subject != requestedID { respondError(w, http.StatusForbidden, "Forbidden") return }