'use strict'; const { UnauthorizedError, NotFoundError } = require('@strapi/utils').errors module.exports = async (policyContext, config, {strapi}) => { const {request, params} = policyContext if (!request?.header?.authorization) { throw new UnauthorizedError('Opération non autorisée') } let jwtUserId try { ({id: jwtUserId} = await strapi.plugins['users-permissions'].services.jwt.getToken(policyContext)) } catch (err) { throw new UnauthorizedError('Opération non autorisée') } const documentId = params?.id ?? request.body?.data?.documentId const document = await strapi.db.query(config.uid).findOne({ where: {documentId}, populate: {user: true} }) if (!document) { throw new NotFoundError('Ressource introuvable.') } if (document.user?.id !== jwtUserId) { throw new UnauthorizedError('Opération non autorisée') } return true }