Let's say I have an endpoint for posting new users with a logic like this:
...
user = new User(_.pick(req.body, ['name', 'email', 'password', 'isAdmin']));
const salt = await bcrypt.genSalt(10);
user.password = await bcrypt.hash(user.password, salt);
await user.save();
const token = user.generateAuthToken();
...
This would work but now of course every user could set the isAdmin flag. Another way would be adding admin users manually to the database but this is probably not the best way.
Is there a recommended way to solve this problem?