router.post('/', cpUpload, auth.isAuthenticated(), controller.create);
router.delete('/:id', auth.isAuthenticated(), controller.destroy);
-router.delete('/', auth.isAuthenticated(), controller.purge);
+router.delete('/', auth.hasRole('admin'), controller.purge);
module.exports = router;
\ No newline at end of file