diff --git a/app/controllers/custom_urls_controller.rb b/app/controllers/custom_urls_controller.rb index b6b1a8d..fc69578 100644 --- a/app/controllers/custom_urls_controller.rb +++ b/app/controllers/custom_urls_controller.rb @@ -1,9 +1,10 @@ class CustomUrlsController < ApplicationController def administrate + raise AccessError unless cuser && cuser.admin? end def create - + raise AccessError unless request.xhr? end def show @@ -15,8 +16,10 @@ class CustomUrlsController < ApplicationController end def update + raise AccessError unless request.xhr? end def destroy + raise AccessError unless request.xhr? end end diff --git a/app/views/about/adminpanel.html.erb b/app/views/about/adminpanel.html.erb index 45035ea..f4b0099 100644 --- a/app/views/about/adminpanel.html.erb +++ b/app/views/about/adminpanel.html.erb @@ -18,5 +18,6 @@