Don't allow destroy if owner is not current user

This commit is contained in:
Justin Edmund 2022-02-23 16:34:36 -08:00
parent 53e6e8bd39
commit 29c3415df2

View file

@ -31,7 +31,11 @@ class Api::V1::PartiesController < Api::V1::ApiController
end
def destroy
render :destroyed, status: :ok if @party.destroy
if @party.user != current_user
render_unauthorized_response
else
render :destroyed, status: :ok if @party.destroy
end
end
def weapons