Check if current_user is the owner of a resource and allow edit/delete actions

后端 未结 9 609
鱼传尺愫
鱼传尺愫 2021-02-02 00:02

Example:

User A (id=10) has created a photo resource

photo: (id: 1 user_id = 10, url: \"http://...\")
         


        
9条回答
  •  死守一世寂寞
    2021-02-02 00:52

    The simplest would be to to modify routes.rb.

    Assign photos to live in the current_user path.

    For example,

    devise_for :users
    
    resources 'users' do 
      resources 'photos'
    end
    

提交回复
热议问题