Fixed incorrect showing of favorite groups
This commit is contained in:
@@ -13,6 +13,7 @@ class FavoriteGroupsController < ApplicationController
|
|||||||
|
|
||||||
def show
|
def show
|
||||||
@favorite_group = FavoriteGroup.find(params[:id])
|
@favorite_group = FavoriteGroup.find(params[:id])
|
||||||
|
check_read_privilege(@favorite_group)
|
||||||
@post_set = PostSets::FavoriteGroup.new(@favorite_group, params[:page])
|
@post_set = PostSets::FavoriteGroup.new(@favorite_group, params[:page])
|
||||||
respond_with(@favorite_group)
|
respond_with(@favorite_group)
|
||||||
end
|
end
|
||||||
@@ -37,13 +38,13 @@ class FavoriteGroupsController < ApplicationController
|
|||||||
|
|
||||||
def edit
|
def edit
|
||||||
@favorite_group = FavoriteGroup.find(params[:id])
|
@favorite_group = FavoriteGroup.find(params[:id])
|
||||||
check_privilege(@favorite_group)
|
check_write_privilege(@favorite_group)
|
||||||
respond_with(@favorite_group)
|
respond_with(@favorite_group)
|
||||||
end
|
end
|
||||||
|
|
||||||
def update
|
def update
|
||||||
@favorite_group = FavoriteGroup.find(params[:id])
|
@favorite_group = FavoriteGroup.find(params[:id])
|
||||||
check_privilege(@favorite_group)
|
check_write_privilege(@favorite_group)
|
||||||
@favorite_group.update_attributes(params[:favorite_group])
|
@favorite_group.update_attributes(params[:favorite_group])
|
||||||
unless @favorite_group.errors.any?
|
unless @favorite_group.errors.any?
|
||||||
flash[:notice] = "Favorite group updated"
|
flash[:notice] = "Favorite group updated"
|
||||||
@@ -53,7 +54,7 @@ class FavoriteGroupsController < ApplicationController
|
|||||||
|
|
||||||
def destroy
|
def destroy
|
||||||
@favorite_group = FavoriteGroup.find(params[:id])
|
@favorite_group = FavoriteGroup.find(params[:id])
|
||||||
check_privilege(@favorite_group)
|
check_write_privilege(@favorite_group)
|
||||||
@favorite_group.destroy
|
@favorite_group.destroy
|
||||||
flash[:notice] = "Favorite group deleted"
|
flash[:notice] = "Favorite group deleted"
|
||||||
redirect_to favorite_groups_path
|
redirect_to favorite_groups_path
|
||||||
@@ -61,13 +62,17 @@ class FavoriteGroupsController < ApplicationController
|
|||||||
|
|
||||||
def add_post
|
def add_post
|
||||||
@favorite_group = FavoriteGroup.find(params[:id])
|
@favorite_group = FavoriteGroup.find(params[:id])
|
||||||
check_privilege(@favorite_group)
|
check_write_privilege(@favorite_group)
|
||||||
@post = Post.find(params[:post_id])
|
@post = Post.find(params[:post_id])
|
||||||
@favorite_group.add!(@post.id)
|
@favorite_group.add!(@post.id)
|
||||||
end
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
def check_privilege(favgroup)
|
def check_write_privilege(favgroup)
|
||||||
raise User::PrivilegeError unless favgroup.editable_by?(CurrentUser.user)
|
raise User::PrivilegeError unless favgroup.editable_by?(CurrentUser.user)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def check_read_privilege(favgroup)
|
||||||
|
raise User::PrivilegeError unless favgroup.viewable_by?(CurrentUser.user)
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -237,4 +237,8 @@ class FavoriteGroup < ApplicationRecord
|
|||||||
def editable_by?(user)
|
def editable_by?(user)
|
||||||
creator_id == user.id
|
creator_id == user.id
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def viewable_by?(user)
|
||||||
|
creator_id == user.id || !creator.hide_favorites?
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -608,11 +608,23 @@ class Tag < ApplicationRecord
|
|||||||
|
|
||||||
when "-favgroup"
|
when "-favgroup"
|
||||||
favgroup_id = FavoriteGroup.name_to_id(g2)
|
favgroup_id = FavoriteGroup.name_to_id(g2)
|
||||||
|
favgroup = FavoriteGroup.find(favgroup_id)
|
||||||
|
|
||||||
|
if !favgroup.viewable_by?(CurrentUser.user)
|
||||||
|
raise User::PrivilegeError.new
|
||||||
|
end
|
||||||
|
|
||||||
q[:favgroups_neg] ||= []
|
q[:favgroups_neg] ||= []
|
||||||
q[:favgroups_neg] << favgroup_id
|
q[:favgroups_neg] << favgroup_id
|
||||||
|
|
||||||
when "favgroup"
|
when "favgroup"
|
||||||
favgroup_id = FavoriteGroup.name_to_id(g2)
|
favgroup_id = FavoriteGroup.name_to_id(g2)
|
||||||
|
favgroup = FavoriteGroup.find(favgroup_id)
|
||||||
|
|
||||||
|
if !favgroup.viewable_by?(CurrentUser.user)
|
||||||
|
raise User::PrivilegeError.new
|
||||||
|
end
|
||||||
|
|
||||||
q[:favgroups] ||= []
|
q[:favgroups] ||= []
|
||||||
q[:favgroups] << favgroup_id
|
q[:favgroups] << favgroup_id
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user