oops add security

This commit is contained in:
Sam 2013-10-21 15:33:42 +11:00
parent 6067795780
commit 29c8d2ebec
2 changed files with 4 additions and 0 deletions

View File

@ -7,7 +7,9 @@
<th class='num topics'>{{i18n categories.topics}}</th>
<th class='num posts'>{{i18n categories.posts}}</th>
<th class='latest'>{{i18n categories.latest}}
{{#if canEdit}}
<button title='{{i18n categories.toggle_ordering}}' class='btn toggle-admin no-text' {{action toggleOrdering}}><i class='icon icon-wrench'></i></button>
{{/if}}
</th>
</tr>
</thead>

View File

@ -29,6 +29,8 @@ class CategoriesController < ApplicationController
end
def move
guardian.ensure_can_create!(Category)
params.require("category_id")
params.require("position")