From 2f07856b67504cc0da9d031ce47c6bf212a49cb7 Mon Sep 17 00:00:00 2001 From: benji Date: Tue, 8 Sep 2015 17:40:40 +0200 Subject: [PATCH] Add authorization to user controller --- app/controllers/users_controller.rb | 2 ++ app/views/layouts/application.html.erb | 4 +++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/app/controllers/users_controller.rb b/app/controllers/users_controller.rb index 3b9390c..d191303 100644 --- a/app/controllers/users_controller.rb +++ b/app/controllers/users_controller.rb @@ -1,4 +1,6 @@ class UsersController < ApplicationController + load_and_authorize_resource + def show @user = User.find(params[:id]) end diff --git a/app/views/layouts/application.html.erb b/app/views/layouts/application.html.erb index 1bf645f..376e9b4 100644 --- a/app/views/layouts/application.html.erb +++ b/app/views/layouts/application.html.erb @@ -8,7 +8,9 @@ -<%= yield %> + <%= content_tag :div, flash[:alert] if flash[:alert] %> + + <%= yield %>