Prevent non-authors from viewing valuation comments
This commit is contained in:
@@ -21,7 +21,11 @@ class CommentsController < ApplicationController
|
|||||||
|
|
||||||
def show
|
def show
|
||||||
@comment = Comment.find(params[:id])
|
@comment = Comment.find(params[:id])
|
||||||
set_comment_flags(@comment.subtree)
|
if @comment.valuation && @comment.author != current_user
|
||||||
|
raise ActiveRecord::RecordNotFound
|
||||||
|
else
|
||||||
|
set_comment_flags(@comment.subtree)
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def vote
|
def vote
|
||||||
|
|||||||
Reference in New Issue
Block a user