fixes per @mlorb 's request

This commit is contained in:
zmagod 2018-01-24 13:21:53 +01:00
parent 259880c441
commit 9b836d04fa
3 changed files with 3 additions and 3 deletions

View file

@ -192,7 +192,7 @@ module Users
@role = params['role']
render_403 if @emails && @emails.empty?
render_403 if @team && !can_read_team?(@team)
render_403 if @team && !can_manage_team_users?(@team)
render_403 if @role && !UserTeam.roles.keys.include?(@role)
end
end

View file

@ -147,7 +147,7 @@ module Users
def load_team
@team = Team.find_by_id(params[:id])
render_403 unless can_read_team?(@team)
render_403 unless can_update_team?(@team)
end
def create_params

View file

@ -150,7 +150,7 @@ module Users
# Don't allow the user to modify UserTeam-s if he's not admin,
# unless he/she is modifying his/her UserTeam
if current_user != @user_t.user &&
!can_read_team?(@user_t.team)
!can_manage_team_users?(@user_t.team)
render_403
end
end