From 04e572bb558fbf2e3972f0b2a0d08c99683ebef9 Mon Sep 17 00:00:00 2001 From: Ari Timonen Date: Mon, 22 Jun 2015 00:43:16 +0300 Subject: [PATCH] Fix access check bug --- app/models/team.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/models/team.rb b/app/models/team.rb index a427900..8715593 100644 --- a/app/models/team.rb +++ b/app/models/team.rb @@ -114,7 +114,7 @@ class Team < ActiveRecord::Base end def can_update? cuser - cuser and is_leader? cuser or cuser.admin? + cuser and (is_leader? cuser or cuser.admin?) end def can_destroy? cuser