Don't allow destroy if owner is not current user
This commit is contained in:
parent
53e6e8bd39
commit
29c3415df2
1 changed files with 5 additions and 1 deletions
|
|
@ -31,7 +31,11 @@ class Api::V1::PartiesController < Api::V1::ApiController
|
|||
end
|
||||
|
||||
def destroy
|
||||
render :destroyed, status: :ok if @party.destroy
|
||||
if @party.user != current_user
|
||||
render_unauthorized_response
|
||||
else
|
||||
render :destroyed, status: :ok if @party.destroy
|
||||
end
|
||||
end
|
||||
|
||||
def weapons
|
||||
|
|
|
|||
Loading…
Reference in a new issue