diff --git a/pitch-deck/app/api/finanzplan/[sheetName]/route.ts b/pitch-deck/app/api/finanzplan/[sheetName]/route.ts index 6893af9..b9d6ad0 100644 --- a/pitch-deck/app/api/finanzplan/[sheetName]/route.ts +++ b/pitch-deck/app/api/finanzplan/[sheetName]/route.ts @@ -48,9 +48,7 @@ export async function GET( return NextResponse.json({ error: `Unknown sheet: ${sheetName}` }, { status: 400 }) } - // Only admin callers may query an arbitrary scenarioId; investors always see the default - const isAdmin = validateAdminSecret(request) - const scenarioId = isAdmin ? request.nextUrl.searchParams.get('scenarioId') : null + const scenarioId = request.nextUrl.searchParams.get('scenarioId') try { let query = `SELECT * FROM ${table}`