diff --git a/src/jobs/jobs.controller.ts b/src/jobs/jobs.controller.ts index 5197c14ee..0619a4f2f 100644 --- a/src/jobs/jobs.controller.ts +++ b/src/jobs/jobs.controller.ts @@ -737,10 +737,10 @@ export class JobsController { const ability = this.caslAbilityFactory.createForUser( request.user as JWTUser, ); - const canGet = + const canRead = ability.can(AuthOp.JobReadAny, JobClass) || ability.can(AuthOp.JobReadAccess, currentJobInstance); - if (!canGet) { + if (!canRead) { throw new ForbiddenException("Unauthorized to get this job."); } return currentJob;