saasbook

moviegoer_owns_review.rb

Apr 6th, 2013
138
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Ruby 0.32 KB | None | 0 0
  1. class ReviewsController < ApplicationController
  2.   before_filter :moviegoer_owns_review, :only => [:edit, :update]
  3.   def moviegoer_owns_review
  4.     unless Review.find_by_id(params[:id]).try(:moviegoer) == @current_user
  5.       flash[:warning] = 'You can only edit your own reviews.'
  6.       redirect_to movies_path
  7.     end
  8.   end
  9. end
Add Comment
Please, Sign In to add comment