diff --git a/routes/users.js b/routes/users.js index 98e67639..d1b38647 100644 --- a/routes/users.js +++ b/routes/users.js @@ -1784,7 +1784,10 @@ router.delete('/user/:id/project/:project', async function(req, res) { res.status(404).send({ message: 'Project not found' }); return; } - + if (project.owner == uid) { + res.status(400).send({ message: 'Can not remove project owner' }); + return; + } if (!isadmin && session_user.uid != project.owner && session_user.uid != uid) { res.status(401).send({ message: 'Not authorized' }); return;