|
@@ -50,6 +50,10 @@ class TeamMemberController extends Controller
|
|
|
{
|
|
|
$teamMember = TeamMember::query()->findOrFail($id);
|
|
|
|
|
|
+ if($teamMember->user_id==$teamMember->created_by){
|
|
|
+ return $this->badRequest('Not allowed to delete project creator');
|
|
|
+ }
|
|
|
+
|
|
|
if ($teamMember->project?->company_id != Auth::user()->company_id) {
|
|
|
return $this->forbidden('No permission to delete');
|
|
|
}
|