diff --git a/authz/authz.go b/authz/authz.go index 8086e56d..2f3e72c1 100644 --- a/authz/authz.go +++ b/authz/authz.go @@ -151,7 +151,7 @@ func isAllowedInDemoMode(subOwner string, subName string, method string, urlPath return true } else if urlPath == "/api/update-user" { // Allow ordinary users to update their own information - if subOwner == objOwner && subName == objName && !(subOwner == "built-in" && subName == "admin") { + if (subOwner == objOwner && subName == objName || subOwner == "app") && !(subOwner == "built-in" && subName == "admin") { return true } return false