From 0c469bc362a073946dc3c3460ead5d7d37d5326f Mon Sep 17 00:00:00 2001 From: kikito Date: Wed, 15 Jun 2016 14:02:13 +0200 Subject: [PATCH] fixes the way permissions work for proposalnotifications --- app/models/abilities/common.rb | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/app/models/abilities/common.rb b/app/models/abilities/common.rb index 994bf90c0..f82e78b58 100644 --- a/app/models/abilities/common.rb +++ b/app/models/abilities/common.rb @@ -50,9 +50,7 @@ module Abilities can :show, DirectMessage, sender_id: user.id end - can [:new, :create, :show], ProposalNotification do |notification| - notification.proposal.author_id == user.id - end + can [:create, :show], ProposalNotification, proposal: { author_id: user.id } can :create, Annotation can [:update, :destroy], Annotation, user_id: user.id