From 6dcd01366ceea0c262483a939e67f3b1153e529a Mon Sep 17 00:00:00 2001 From: Bertocq Date: Wed, 24 Jan 2018 16:51:23 +0100 Subject: [PATCH] Preven admins from destroying others images&docs --- app/models/abilities/administrator.rb | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/app/models/abilities/administrator.rb b/app/models/abilities/administrator.rb index 3f136f913..53b49dfb4 100644 --- a/app/models/abilities/administrator.rb +++ b/app/models/abilities/administrator.rb @@ -80,8 +80,7 @@ module Abilities can [:manage], ::Legislation::Proposal cannot :comment_as_moderator, [::Legislation::Question, Legislation::Annotation, ::Legislation::Proposal] - can [:create, :destroy], Document - can [:destroy], Image + can [:create], Document can [:create, :destroy], DirectUpload end end