diff --git a/app/controllers/admin/galleries_controller.rb b/app/controllers/admin/galleries_controller.rb index 15548e4..9865101 100644 --- a/app/controllers/admin/galleries_controller.rb +++ b/app/controllers/admin/galleries_controller.rb @@ -41,9 +41,12 @@ class Admin::GalleriesController < OrbitAdminController def edit @album = Album.find(params[:id]) - @tags = @module_app.tags - @categories = @module_app.categories - + if can_edit_or_delete?(@album) + @tags = @module_app.tags + @categories = @module_app.categories + else + render_401 + end end def set_cover