权限判断

dev_aliyun2
daiao 5 years ago committed by harry
parent df04e495d2
commit 78feda4231

@ -55,7 +55,7 @@ class Users::VideosController < Users::BaseController
def destroy
video = Video.find_by(id: params[:id])
render_forbidden unless video.user_id != observed_user.id || !current_user.admin_or_business?
return render_forbidden unless video.user_id == current_user.id || current_user.admin_or_business?
return render_not_found if video.blank?
return render_error('该状态下不能删除视频') unless video.pending?

Loading…
Cancel
Save