Hi, me again Lol, So I have this query to update a...
# orm-help
l
Hi, me again Lol, So I have this query to update a record something like this, I want to ensure that only the user who created it, can authorize the edit.
Copy code
const {userId} = context  
    const updatedSavedLink = await context.prisma.savedLink.update({
        where: {
            id: args.savedLinkId,
           // adding userId: userId throws error 
        },
        data: {
            note: args.note ? args.note.trim() : null
        }
    })
This is how the schema looks like:
Copy code
model SavedLink {
  id        String   @id @default(uuid())
  createdAt DateTime @default(now())
  link      Link     @relation(fields: [linkId], references: [id])
  linkId    String
  user      User     @relation(fields: [userId], references: [id])
  userId    String
  note      String?

  @@unique([id, userId])
}
r
Are you using some sort of authorisation middleware like graphql-shield?
l
Yeah, I am.
like, is it better to check that on the graphql layer, than adding an extra where condition in the query?
r
Better to check on the shield layer where you can easily add a rule like
isPostAuthor
That would be the best way.
🙌 1
l
Thanks!! 🙂
🙌 1