@@ -3610,7 +3610,7 @@ export class Message {
36103610 }
36113611 const tuser = Crypt . verityToken ( jwt ) ;
36123612 if ( ! tuser . HasRoleName ( customer . name + " admins" ) && ! tuser . HasRoleName ( "admins" ) ) {
3613- throw new Error ( "Access denied, adding plan (admins)" ) ;
3613+ throw new Error ( "Access denied, adding plan (not in '" + customer . name + " admins' )") ;
36143614 }
36153615
36163616
@@ -3736,7 +3736,7 @@ export class Message {
37363736
37373737 const user = Crypt . verityToken ( cli . jwt ) ;
37383738 if ( ! user . HasRoleName ( customer . name + " admins" ) && ! user . HasRoleName ( "admins" ) ) {
3739- throw new Error ( "Access denied, getting invoice (admins)" ) ;
3739+ throw new Error ( "Access denied, getting invoice (not in '" + customer . name + " admins' )") ;
37403740 }
37413741
37423742 let subscription : stripe_subscription ;
@@ -3945,7 +3945,7 @@ export class Message {
39453945
39463946 const tuser = Crypt . verityToken ( jwt ) ;
39473947 if ( ! tuser . HasRoleName ( customer . name + " admins" ) && ! tuser . HasRoleName ( "admins" ) ) {
3948- throw new Error ( "Access denied, adding plan (admins)" ) ;
3948+ throw new Error ( "Access denied, adding plan (not in '" + customer . name + " admins' )") ;
39493949 }
39503950
39513951 if ( NoderedUtil . IsNullEmpty ( customer . vattype ) ) customer . vattype = "" ;
@@ -4328,7 +4328,7 @@ export class Message {
43284328 if ( ! NoderedUtil . IsNullEmpty ( tuser . selectedcustomerid ) && customer == null ) customer = await Config . db . getbyid ( tuser . customerid , "users" , cli . jwt , true , null ) ;
43294329 if ( customer == null ) throw new Error ( "Access denied, or customer not found" ) ;
43304330 if ( ! tuser . HasRoleName ( customer . name + " admins" ) && ! tuser . HasRoleName ( "admins" ) ) {
4331- throw new Error ( "Access denied, adding plan (admins)" ) ;
4331+ throw new Error ( "Access denied, adding plan (not in '" + customer . name + " admins' )") ;
43324332 }
43334333 }
43344334 if ( msg . object == "subscription_items" && msg . method != "POST" ) throw new Error ( "Access to " + msg . object + " is not allowed" ) ;
0 commit comments