FIX delete message permission

dev_forum
jasder 5 years ago
parent 8d6ddd2938
commit 029aac3554

@ -128,7 +128,7 @@ class MessagesController < ApplicationController
def destroy
begin
return normal_status(403, "您没有权限进行该操作") unless @message.author == current_user || current_user.teacher_of_course?(@message.board.course)
return normal_status(403, "您没有权限进行该操作") if current_user.course_identity(@message.board.course) >= 5 || @message.author != current_user
@message.destroy!
rescue Exception => e
uid_logger_error(e.message)

Loading…
Cancel
Save