diff --git a/app/controllers/new_user/dossiers_controller.rb b/app/controllers/new_user/dossiers_controller.rb index 0c9aadfea..754d53925 100644 --- a/app/controllers/new_user/dossiers_controller.rb +++ b/app/controllers/new_user/dossiers_controller.rb @@ -103,7 +103,7 @@ module NewUser end def ensure_ownership! - if dossier.user_id != current_user.id + if !owns_dossier? forbidden! end end @@ -127,6 +127,10 @@ module NewUser params.require(:dossier).permit(:autorisation_donnees) end + def owns_dossier? + dossier.user_id == current_user.id + end + def draft? params[:submit_action] == 'draft' end