Don't allow users to see each others balances
This commit is contained in:
parent
008f56a563
commit
51a045dae9
1 changed files with 1 additions and 1 deletions
|
@ -4,7 +4,7 @@ class UsersController < ApplicationController
|
|||
before_action :authenticate_user!, except: :show
|
||||
before_action :authenticate_user_or_client!, only: :show
|
||||
|
||||
load_and_authorize_resource except: :show, find_by: :name
|
||||
load_and_authorize_resource find_by: :name
|
||||
|
||||
def show
|
||||
@user = User.find_by(name: params[:id]) || User.new
|
||||
|
|
Loading…
Reference in a new issue