master
Alinson S. Xavier 18 years ago
parent ec73cf67cb
commit 05b3200b7b

@ -40,8 +40,7 @@ class UsersController < ApplicationController
end end
def update def update
params[:user][:login].downcase! raise AccessDenied.new unless params[:user][:login].nil?
raise AccessDenied.new unless (params[:user][:login] == @user.login)
raise AccessDenied.new unless (params[:user][:admin].nil? or @current_user.admin?) raise AccessDenied.new unless (params[:user][:admin].nil? or @current_user.admin?)
@user.admin = !params[:user][:admin].nil? @user.admin = !params[:user][:admin].nil?