summaryrefslogtreecommitdiff
path: root/app/controllers/groups/group_members_controller.rb
diff options
context:
space:
mode:
authorDouwe Maan <douwe@gitlab.com>2015-07-31 14:15:49 +0200
committerDouwe Maan <douwe@gitlab.com>2015-07-31 14:15:49 +0200
commit0736f348a6953e6417d3857b78ea5c7eb5954e51 (patch)
treeb4fdb1879a5e5cc8ceefd5a219a01142ea6baecc /app/controllers/groups/group_members_controller.rb
parentd953f6927cfa605d0bc336b09a25bde2a483b3ba (diff)
downloadgitlab-ce-0736f348a6953e6417d3857b78ea5c7eb5954e51.tar.gz
Use before_actions
Diffstat (limited to 'app/controllers/groups/group_members_controller.rb')
-rw-r--r--app/controllers/groups/group_members_controller.rb5
1 files changed, 1 insertions, 4 deletions
diff --git a/app/controllers/groups/group_members_controller.rb b/app/controllers/groups/group_members_controller.rb
index b9c428a964f..91518c44a98 100644
--- a/app/controllers/groups/group_members_controller.rb
+++ b/app/controllers/groups/group_members_controller.rb
@@ -5,6 +5,7 @@ class Groups::GroupMembersController < Groups::ApplicationController
# Authorize
before_action :authorize_read_group!
before_action :authorize_admin_group!, except: [:index, :leave]
+ before_action :authorize_admin_group_member!, only: [:create, :resend_invite]
def index
@project = @group.projects.find(params[:project_id]) if params[:project_id]
@@ -21,8 +22,6 @@ class Groups::GroupMembersController < Groups::ApplicationController
end
def create
- return render_403 unless can?(current_user, :admin_group_member, @group)
-
@group.add_users(params[:user_ids].split(','), params[:access_level], current_user)
redirect_to group_group_members_path(@group), notice: 'Users were successfully added.'
@@ -51,8 +50,6 @@ class Groups::GroupMembersController < Groups::ApplicationController
end
def resend_invite
- return render_403 unless can?(current_user, :admin_group_member, @group)
-
redirect_path = group_group_members_path(@group)
@group_member = @group.group_members.find(params[:id])