forked from saurabh/orbit4-5
fixed authorizations
This commit is contained in:
parent
26192b8757
commit
58bea99430
|
@ -138,8 +138,11 @@ module OrbitBackendHelper
|
|||
end
|
||||
|
||||
def can_edit_or_delete?(obj)
|
||||
create_user = obj.create_user_id.to_s rescue nil
|
||||
if @user_authenticated_categories.first == "all"
|
||||
return true
|
||||
elsif current_user.is_sub_manager?(@module_app) && !create_user.nil?
|
||||
create_user == current_user.id.to_s
|
||||
else
|
||||
@user_authenticated_categories.include?obj.category_id rescue (current_user.is_manager?(@module_app) rescue false)
|
||||
end
|
||||
|
|
Loading…
Reference in New Issue