Files
astuto/app/policies/tenant_setting_policy.rb
2023-02-04 15:43:15 +01:00

13 lines
230 B
Ruby

class TenantSettingPolicy < ApplicationPolicy
def permitted_attributes_for_update
if user.admin?
[:brand_display]
else
[]
end
end
def update?
user.admin? and user.tenant_id == record.id
end
end