Disallow status change for self

This commit is contained in:
cryptogopher 2023-05-21 16:51:21 +02:00
parent 9d97eb3f6f
commit 479c159f78

View File

@ -17,6 +17,7 @@ class UsersController < ApplicationController
end
def update
raise ArgumentError if current_user == @user
@user.update!(params.require(:user).permit(:status))
end