Fixed policy for controller admin/update

This commit is contained in:
2024-09-19 08:10:25 +02:00
parent e5bd21823c
commit f307ff9e68

View File

@@ -24,7 +24,7 @@ class Admin::UsersController < ApplicationController
end
def update
authorize! @user
authorize! @user, to: :change_role?
if @user.update(user_params)
respond_to do |format|
format.html { redirect_back(fallback_location: admin_users_path) }