added security fix for edit
This commit is contained in:
parent
dd60393057
commit
94855f8900
|
@ -11,8 +11,12 @@ class Admin::AdImagesController < Admin::AdBannersController
|
||||||
|
|
||||||
def edit
|
def edit
|
||||||
@ad_image = AdImage.find(params[:id])
|
@ad_image = AdImage.find(params[:id])
|
||||||
|
if can_edit_or_delete?(@ad_image)
|
||||||
@ad_banners = Banner.all
|
@ad_banners = Banner.all
|
||||||
@tags = @module_app.tags || []
|
@tags = @module_app.tags || []
|
||||||
|
else
|
||||||
|
render_401
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def update
|
def update
|
||||||
|
|
Loading…
Reference in New Issue