Files
astuto/app/policies/post_policy.rb

21 lines
440 B
Ruby
Raw Normal View History

2022-06-10 12:03:33 +02:00
class PostPolicy < ApplicationPolicy
def permitted_attributes_for_create
[:title, :description, :board_id]
end
def permitted_attributes_for_update
2023-01-18 21:11:27 +01:00
if user.moderator?
2024-07-12 20:38:46 +02:00
[:title, :description, :board_id, :post_status_id, :approval_status]
else
[:title, :description]
end
end
2022-06-10 12:03:33 +02:00
def update?
2023-01-18 21:11:27 +01:00
user == record.user or user.moderator?
2022-06-10 12:03:33 +02:00
end
def destroy?
2023-01-18 21:11:27 +01:00
user == record.user or user.moderator?
end
2022-06-10 12:03:33 +02:00
end