summaryrefslogtreecommitdiff
path: root/users/app/controllers
diff options
context:
space:
mode:
authorjessib <jessib@riseup.net>2013-02-26 10:45:52 -0800
committerjessib <jessib@riseup.net>2013-02-26 10:45:52 -0800
commit994f8d23a5a961b8656136eae2aec56204293c52 (patch)
tree09a6cbcd6c4fad8fcf130d6c2d268afe025886ca /users/app/controllers
parent5dbbf733a6abe809a38667e8b3277fd06db24788 (diff)
parent73e9332dadde9f37a85753faf40b9b6b2d73dd88 (diff)
Merge pull request #28 from leapcode/feature/change_login
Feature/change login
Diffstat (limited to 'users/app/controllers')
-rw-r--r--users/app/controllers/users_controller.rb8
1 files changed, 7 insertions, 1 deletions
diff --git a/users/app/controllers/users_controller.rb b/users/app/controllers/users_controller.rb
index 9325bc0..dff1ed5 100644
--- a/users/app/controllers/users_controller.rb
+++ b/users/app/controllers/users_controller.rb
@@ -1,7 +1,8 @@
class UsersController < ApplicationController
- before_filter :authorize, :only => [:show, :edit, :update, :destroy]
+ before_filter :authorize, :only => [:show, :edit, :destroy, :update]
before_filter :fetch_user, :only => [:show, :edit, :update, :destroy]
+ before_filter :authorize_self, :only => [:update]
before_filter :set_anchor, :only => [:edit, :update]
before_filter :authorize_admin, :only => [:index]
@@ -57,6 +58,11 @@ class UsersController < ApplicationController
access_denied unless admin? or (@user == current_user)
end
+ def authorize_self
+ # have already checked that authorized
+ access_denied unless (@user == current_user)
+ end
+
def set_anchor
@anchor = email_settings? ? :email : :account
end