Feature #3848 » 0002-Access-params-time_entry-only-if-editing-a-time-entr.patch
app/controllers/issues_controller.rb | ||
---|---|---|
177 | 177 |
end |
178 | 178 | |
179 | 179 |
if request.post? |
180 |
if User.current.allowed_to?(:edit_time_entries, @project) |
|
180 |
if User.current.allowed_to?(:edit_time_entries, @project) and params[:time_entry]
|
|
181 | 181 |
user = User.find(Hash[params[:time_entry].to_a]["user_id"].to_i) |
182 | 182 |
else |
183 | 183 |
# TODO: Maybe I should throw an exception if the current user |