Merge pull request #2775 from evazion/fix-user-feedbacks

Prevent mods from editing/deleting feedbacks given to themselves.
This commit is contained in:
Albert Yi
2016-11-28 12:02:47 -08:00
committed by GitHub
5 changed files with 24 additions and 4 deletions

View File

@@ -49,6 +49,6 @@ class UserFeedbacksController < ApplicationController
private
def check_privilege(user_feedback)
raise User::PrivilegeError unless (user_feedback.creator_id == CurrentUser.id || CurrentUser.is_moderator?)
raise User::PrivilegeError unless user_feedback.editable_by?(CurrentUser.user)
end
end