mirror of
https://github.com/discourse/discourse.git
synced 2025-05-21 18:12:32 +08:00
oops add security
This commit is contained in:
@ -29,6 +29,8 @@ class CategoriesController < ApplicationController
|
||||
end
|
||||
|
||||
def move
|
||||
guardian.ensure_can_create!(Category)
|
||||
|
||||
params.require("category_id")
|
||||
params.require("position")
|
||||
|
||||
|
Reference in New Issue
Block a user