From 8af795e2aceb45ac93aef71cc99efd1c397a51fa Mon Sep 17 00:00:00 2001 From: spen Date: Thu, 8 May 2014 10:46:08 +0800 Subject: [PATCH] fix backend edit authorized --- app/controllers/panel/er_email/back_end/email_ers_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/panel/er_email/back_end/email_ers_controller.rb b/app/controllers/panel/er_email/back_end/email_ers_controller.rb index 056459d..46e6e05 100644 --- a/app/controllers/panel/er_email/back_end/email_ers_controller.rb +++ b/app/controllers/panel/er_email/back_end/email_ers_controller.rb @@ -92,7 +92,7 @@ class Panel::ErEmail::BackEnd::EmailErsController < OrbitBackendController is_authorized_sub_manager = @email_er.category.auth_sub_manager.authorized_user_ids rescue nil - if !(is_manager? || is_admin? || is_authorized_sub_manager.include?(current_user.id)) + if !(is_manager? || is_admin? || (is_authorized_sub_manager.include?(current_user.id) and @email_er.create_user_id == current_user.id)) redirect_to :action => :index else # @summary_variable = @bulletin.summary_variable