Overwrite the default strategies/users-permissions behavior

Hello @CrisLi and welcome to the Strapi Forums :wave:
I would suggest use middleware or a policy to deal with what you are checking.
The middleware and the policy has access to the request, so then you can say, if it exists allow the request if not don’t.

So overwriting the files you are doing I don’t think is nessary