Don't allow destroy if owner is not current user
This commit is contained in:
parent
53e6e8bd39
commit
29c3415df2
1 changed files with 5 additions and 1 deletions
|
|
@ -31,7 +31,11 @@ class Api::V1::PartiesController < Api::V1::ApiController
|
||||||
end
|
end
|
||||||
|
|
||||||
def destroy
|
def destroy
|
||||||
render :destroyed, status: :ok if @party.destroy
|
if @party.user != current_user
|
||||||
|
render_unauthorized_response
|
||||||
|
else
|
||||||
|
render :destroyed, status: :ok if @party.destroy
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def weapons
|
def weapons
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue