oops add security

This commit is contained in:
Sam
2013-10-21 15:33:42 +11:00
parent 6067795780
commit 29c8d2ebec
2 changed files with 4 additions and 0 deletions

View File

@ -29,6 +29,8 @@ class CategoriesController < ApplicationController
end
def move
guardian.ensure_can_create!(Category)
params.require("category_id")
params.require("position")