diff --git a/app/controllers/budgets/results_controller.rb b/app/controllers/budgets/results_controller.rb index aa94eb68b..d92232f67 100644 --- a/app/controllers/budgets/results_controller.rb +++ b/app/controllers/budgets/results_controller.rb @@ -4,6 +4,7 @@ module Budgets load_and_authorize_resource :budget def show + authorize! :read_results, @budget @result = load_result end diff --git a/app/models/abilities/everyone.rb b/app/models/abilities/everyone.rb index 30d295986..c22a3f7e4 100644 --- a/app/models/abilities/everyone.rb +++ b/app/models/abilities/everyone.rb @@ -17,6 +17,7 @@ module Abilities can [:read], Budget can [:read], Budget::Group can [:read, :print], Budget::Investment + can :read_results, Budget, phase: "finished" can :new, DirectMessage can [:read, :debate, :draft_publication, :allegations, :final_version_publication], Legislation::Process can [:read, :changes, :go_to_version], Legislation::DraftVersion