SECURITY: Prevent access to other user's bookmark lists

This commit is contained in:
Martin Brennan
2020-03-19 10:59:32 +10:00
parent 8ae472bc41
commit 8769ca08bb
4 changed files with 26 additions and 2 deletions

View File

@ -1397,6 +1397,7 @@ class UsersController < ApplicationController
def bookmarks
user = fetch_user_from_params
guardian.ensure_can_edit!(user)
respond_to do |format|
format.json do