diff --git a/authz/authz.go b/authz/authz.go index 18177a5b..57a44d5f 100644 --- a/authz/authz.go +++ b/authz/authz.go @@ -160,7 +160,7 @@ func IsAllowed(subOwner string, subName string, method string, urlPath string, o func isAllowedInDemoMode(subOwner string, subName string, method string, urlPath string, objOwner string, objName string) bool { if method == "POST" { - if strings.HasPrefix(urlPath, "/api/login") || urlPath == "/api/logout" || urlPath == "/api/signup" || urlPath == "/api/send-verification-code" { + if strings.HasPrefix(urlPath, "/api/login") || urlPath == "/api/logout" || urlPath == "/api/signup" || urlPath == "/api/send-verification-code" || urlPath == "/api/send-email" { return true } else if urlPath == "/api/update-user" { // Allow ordinary users to update their own information