Files
astuto/app/policies/comment_policy.rb
2023-01-18 21:11:27 +01:00

25 lines
455 B
Ruby

class CommentPolicy < ApplicationPolicy
def permitted_attributes_for_create
if user.moderator?
[:body, :parent_id, :is_post_update]
else
[:body, :parent_id]
end
end
def permitted_attributes_for_update
if user.moderator?
[:body, :is_post_update]
else
[:body]
end
end
def update?
user == record.user or user.moderator?
end
def destroy?
user == record.user or user.moderator?
end
end