Use scoped view for StudyPolicy to prevent leaking other groups
This commit is contained in:
@ -4,7 +4,7 @@ class StudyGroupsController < ApplicationController
|
|||||||
before_action :set_group, only: MEMBER_ACTIONS
|
before_action :set_group, only: MEMBER_ACTIONS
|
||||||
|
|
||||||
def index
|
def index
|
||||||
@search = StudyGroup.ransack(params[:q])
|
@search = policy_scope(StudyGroup).ransack(params[:q])
|
||||||
@study_groups = @search.result.includes(:consumer).order(:name).paginate(page: params[:page])
|
@study_groups = @search.result.includes(:consumer).order(:name).paginate(page: params[:page])
|
||||||
authorize!
|
authorize!
|
||||||
end
|
end
|
||||||
|
Reference in New Issue
Block a user