diff --git a/app/controllers/admin/vouchers_controller.rb b/app/controllers/admin/vouchers_controller.rb index 66908db7ff..efd9ac9b7d 100644 --- a/app/controllers/admin/vouchers_controller.rb +++ b/app/controllers/admin/vouchers_controller.rb @@ -26,7 +26,10 @@ module Admin private def load_enterprise - @enterprise = Enterprise.find_by(permalink: params[:enterprise_id]) + @enterprise = OpenFoodNetwork::Permissions + .new(spree_current_user) + .editable_enterprises + .find_by(permalink: params[:enterprise_id]) end def permitted_resource_params