mirror of
https://github.com/openfoodfoundation/openfoodnetwork
synced 2026-03-19 04:49:15 +00:00
Re-add object-level auth to Spree::Admin::ResourceController
This commit is contained in:
16
app/controllers/spree/admin/resource_controller_decorator.rb
Normal file
16
app/controllers/spree/admin/resource_controller_decorator.rb
Normal file
@@ -0,0 +1,16 @@
|
||||
module AuthorizeOnLoadResource
|
||||
def load_resource
|
||||
super
|
||||
|
||||
if member_action?
|
||||
# If we don't have access, clear the object
|
||||
unless can? action, @object
|
||||
instance_variable_set("@#{object_name}", nil)
|
||||
end
|
||||
|
||||
authorize! action, @object
|
||||
end
|
||||
end
|
||||
end
|
||||
|
||||
Spree::Admin::ResourceController.send(:prepend, AuthorizeOnLoadResource)
|
||||
Reference in New Issue
Block a user