Abilities extended. Resources security improved

This commit is contained in:
Dmitriy Zaporozhets 2012-02-22 00:31:18 +02:00
parent af82b6773b
commit 8c40aab120
16 changed files with 51 additions and 52 deletions

View file

@ -112,12 +112,11 @@ class MergeRequestsController < ApplicationController
end
def authorize_modify_merge_request!
can?(current_user, :modify_merge_request, @merge_request) ||
@merge_request.assignee == current_user
return render_404 unless can?(current_user, :modify_merge_request, @merge_request)
end
def authorize_admin_merge_request!
can?(current_user, :admin_merge_request, @merge_request)
return render_404 unless can?(current_user, :admin_merge_request, @merge_request)
end
def module_enabled