From ce4621858dfcde9d901e048600cef57c60c8d51e Mon Sep 17 00:00:00 2001 From: Andy Brett Date: Thu, 14 Jan 2021 14:40:37 -0800 Subject: [PATCH] base authorization on the payment's order --- app/controllers/payments_controller.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/payments_controller.rb b/app/controllers/payments_controller.rb index 000ea22ffb..c0fb7eadcc 100644 --- a/app/controllers/payments_controller.rb +++ b/app/controllers/payments_controller.rb @@ -9,7 +9,7 @@ class PaymentsController < BaseController def redirect_to_authorize @payment = Spree::Payment.find(params[:id]) - authorize! :show, @payment + authorize! :show, @payment.order if url = @payment.cvv_response_message redirect_to url