diff --git a/application/Api/v1/AddressdbApicontroller.php b/application/Api/v1/AddressdbApicontroller.php index 156b4f1ee..43a86d6b4 100644 --- a/application/Api/v1/AddressdbApicontroller.php +++ b/application/Api/v1/AddressdbApicontroller.php @@ -911,8 +911,11 @@ class AddressdbApicontroller extends mfBaseApicontroller { if(!$netop) { $netop = PreordercampaignOperatorModel::getFirst(["operator_id" => $this->me->address_id, "preordercampaign_id" => $campaign->id]); } + if(!$netop) { - return mfResponse::Unauthorized(); + if($campaign->network->owner_id != $this->me->address_id) { + return mfResponse::Unauthorized(); + } } $netoperator = $netop->operator;