Lock down the controllers

This commit is contained in:
Martin Lensment 2014-12-19 13:45:17 +02:00
parent 3045c08b3e
commit 3b1e632ab7
36 changed files with 166 additions and 97 deletions

View file

@ -1,4 +1,5 @@
class Admin::UsersController < AdminController
load_and_authorize_resource
before_action :set_user, only: [:show, :edit, :update, :destroy]
def index
@ -54,6 +55,6 @@ class Admin::UsersController < AdminController
def user_params
params.require(:user).permit(:username, :password, :identity_code, :email,
:admin, :country_id)
:role_id, :country_id)
end
end