Sha256: c295886897a87419e998c090d4746833e721278c9d762dc5e53bf01412050a02
Contents?: true
Size: 994 Bytes
Versions: 11
Compression:
Stored size: 994 Bytes
Contents
class UsersController < ApplicationController before_filter :authenticate_user! after_action :verify_authorized, except: [:show] def index @users = User.all authorize @users end def show @user = User.find(params[:id]) unless current_user.admin? unless @user == current_user redirect_to :back, :alert => "Access denied." end end end def update @user = User.find(params[:id]) authorize @user if @user.update_attributes(secure_params) redirect_to users_path, :notice => "User updated." else redirect_to users_path, :alert => "Unable to update user." end end def destroy user = User.find(params[:id]) authorize user unless user == current_user user.destroy redirect_to users_path, :notice => "User deleted." else redirect_to users_path, :notice => "Can't delete yourself." end end private def secure_params params.require(:user).permit(:role) end end
Version data entries
11 entries across 11 versions & 1 rubygems