diff --git a/app/controllers/files_controller.rb b/app/controllers/files_controller.rb index c8fd042ea..2af178e47 100644 --- a/app/controllers/files_controller.rb +++ b/app/controllers/files_controller.rb @@ -200,7 +200,7 @@ class FilesController < ApplicationController # 资源设置 def update - return normal_status(403, "您没有权限进行该操作") unless current_user.teacher_or_admin?(@course) || @file.author == current_user + return normal_status(403, "您没有权限进行该操作") if current_user.course_identity(@course) >= 5 && @file.author != current_user is_unified_setting = params[:is_unified_setting] publish_time = params[:publish_time]