From c05eb777fc994bf818e730154968839134ed9e85 Mon Sep 17 00:00:00 2001 From: Larissa Reis Date: Tue, 29 Jul 2014 12:53:55 -0300 Subject: [PATCH] spread-functionality: fixes permissions --- app/controllers/my_profile/cms_controller.rb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/controllers/my_profile/cms_controller.rb b/app/controllers/my_profile/cms_controller.rb index 32f6ed1..a433d48 100644 --- a/app/controllers/my_profile/cms_controller.rb +++ b/app/controllers/my_profile/cms_controller.rb @@ -27,7 +27,7 @@ class CmsController < MyProfileController (user && (user.has_permission?('post_content', profile) || user.has_permission?('publish_content', profile))) end - protect_if :except => [:suggest_an_article, :set_home_page, :edit, :destroy, :publish, :upload_files, :new] do |c, user, profile| + protect_if :except => [:suggest_an_article, :set_home_page, :edit, :destroy, :publish, :publish_on_portal_community, :publish_on_communities, :search_communities_to_publish, :upload_files, :new] do |c, user, profile| user && (user.has_permission?('post_content', profile) || user.has_permission?('publish_content', profile)) end @@ -37,7 +37,7 @@ class CmsController < MyProfileController (user && (user.has_permission?('post_content', profile) || user.has_permission?('publish_content', profile))) end - protect_if :only => [:destroy, :publish] do |c, user, profile| + protect_if :only => :destroy do |c, user, profile| profile.articles.find(c.params[:id]).allow_post_content?(user) end -- libgit2 0.21.2