From 519ed365cc71605cd4bbac064e6fe74d59eecad3 Mon Sep 17 00:00:00 2001 From: huang Date: Fri, 13 May 2016 17:24:12 +0800 Subject: [PATCH] =?UTF-8?q?=E5=AF=BC=E5=85=A5=E8=B5=84=E6=BA=90=E6=8C=89?= =?UTF-8?q?=E9=92=AE=E7=82=B9=E5=87=BB=E6=B2=A1=E5=8F=8D=E5=BA=94=E9=97=AE?= =?UTF-8?q?=E9=A2=98?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- app/controllers/users_controller.rb | 3 ++- app/views/repositories/show.html.erb | 2 +- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/app/controllers/users_controller.rb b/app/controllers/users_controller.rb index a461903a9..e498ace44 100644 --- a/app/controllers/users_controller.rb +++ b/app/controllers/users_controller.rb @@ -2780,7 +2780,8 @@ class UsersController < ApplicationController # 导入资源 def import_resources # 别人的资源库是没有权限去看的 - if User.current.id.to_i != params[:id].to_i + user = User.find_by_login(params[:id]) + if User.current != user render_403 return end diff --git a/app/views/repositories/show.html.erb b/app/views/repositories/show.html.erb index 6fed85acf..276283e97 100644 --- a/app/views/repositories/show.html.erb +++ b/app/views/repositories/show.html.erb @@ -1,7 +1,7 @@ <%= call_hook(:view_repositories_show_contextual, {:repository => @repository, :project => @project}) %>

<%= render :partial => 'breadcrumbs', :locals => {:path => @path, :kind => 'dir', :revision => @rev} %>

- ZIP下载 +