From a5c4d3e5fcfe2c9cfd8849aa53238733f8975954 Mon Sep 17 00:00:00 2001 From: Marcela Ribeiro de Oliveira <mro15@inf.ufpr.br> Date: Wed, 5 Jul 2017 09:25:42 -0300 Subject: [PATCH] only submitter can create or update learning_objects --- app/policies/learning_object_policy.rb | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/policies/learning_object_policy.rb b/app/policies/learning_object_policy.rb index 43aaf53e..8e217762 100644 --- a/app/policies/learning_object_policy.rb +++ b/app/policies/learning_object_policy.rb @@ -19,11 +19,11 @@ class LearningObjectPolicy < ApplicationPolicy end def create? - record if user_exists? + record if user_exists? && user.is_submitter? end def update? - record if owns? + record if owns? && user.is_submitter? end def publish? -- GitLab