Add check for edit permission

This commit is contained in:
Anton Ignatov 2019-06-20 09:43:23 +02:00
parent 6f1f6e297c
commit 3069ec8dd2

View file

@ -14,7 +14,7 @@ class AssetsController < ApplicationController
before_action :load_vars, except: :create_wopi_file
before_action :check_read_permission, except: :file_present
before_action :check_edit_permission, only: :edit
before_action :check_edit_permission, only: %i(edit create_start_edit_image_activity)
def file_present
return render_403 unless @asset.team == current_team