Add restore file permission check [SCI-11042]

This commit is contained in:
Martin Artnik 2024-09-18 13:36:49 +02:00 committed by GitHub
parent 48fb68c07c
commit 9aa43f4c36
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -18,7 +18,7 @@ class AssetsController < ApplicationController
before_action :load_vars, except: :create_wopi_file
before_action :check_read_permission, except: %i(edit destroy duplicate create_wopi_file toggle_view_mode)
before_action :check_manage_permission, only: %i(edit destroy duplicate rename toggle_view_mode)
before_action :check_manage_permission, only: %i(edit destroy duplicate rename toggle_view_mode restore_version)
def file_preview
editable = can_manage_asset?(@asset) && (@asset.repository_asset_value.blank? ||