Enforce restrictions on issue visibility properly

This commit is contained in:
Tom Hughes 2020-03-01 19:08:40 +00:00
parent 75d1893343
commit 06122fc090
3 changed files with 131 additions and 23 deletions

View file

@ -80,6 +80,8 @@ class IssuesController < ApplicationController
private
def find_issue
@issue = Issue.find(params[:id])
@issue = Issue.visible_to(current_user).find(params[:id])
rescue ActiveRecord::RecordNotFound
head :not_found
end
end