diff --git a/app/v1/user.go b/app/v1/user.go index 2db14ac..6d068de 100644 --- a/app/v1/user.go +++ b/app/v1/user.go @@ -140,7 +140,7 @@ func UserWhatsTheIDGET(md common.MethodData) common.Response { allowed int ) err := md.DB.QueryRow("SELECT id, allowed FROM users WHERE username = ? LIMIT 1", md.C.Param("username")).Scan(&id, &allowed) - if err != nil || allowed != 1 { + if err != nil || (allowed != 1 && !md.User.Privileges.HasPrivilegeViewUserAdvanced()) { return common.Response{ Code: 404, Message: "That user could not be found!",