X-Git-Url: https://projects.mako.cc/source/selectricity/blobdiff_plain/b6c33d42dd37f1fb10db479c5d6b7fb4c660beb9..b82ac70a3367072882aa259dae0b6a1b6e3288fa:/app/controllers/account_controller.rb diff --git a/app/controllers/account_controller.rb b/app/controllers/account_controller.rb index ce4303d..4b7fea9 100644 --- a/app/controllers/account_controller.rb +++ b/app/controllers/account_controller.rb @@ -60,7 +60,17 @@ class AccountController < ApplicationController #The following methods are for selectricity specific uses def summary - @user = User.find(params[:id]) + #@user = User.find(params[:id]) + + #constrain the find command such that it only returns the user if it's the currently + #logged in user, otherwise, redirect to the front page + id = params[:id] + user_id = session[:user][:id] + @user = User.find(id, :conditions => ["id = ?", user_id]) + + rescue + redirect_to :controller =>'front' + end def change_contact