app/controllers/spree/api/payments_controller.rb in spree_api-2.2.1 vs app/controllers/spree/api/payments_controller.rb in spree_api-2.2.2
- old
+ new
@@ -64,10 +64,10 @@
end
private
def find_order
- @order = Spree::Order.find_by(number: params[:order_id])
+ @order = Spree::Order.find_by(number: order_id)
authorize! :read, @order
end
def find_payment
@payment = @order.payments.find(params[:id])