check if user is allowed to view assets (#4845)

This commit is contained in:
vcordes79 2018-01-24 03:10:05 +01:00 committed by snipe
parent f4e9d245d0
commit 0fb8dc3418

View file

@ -286,6 +286,7 @@ class UsersController extends Controller
{
$this->authorize('view', User::class);
$assets = Asset::where('assigned_to', '=', $id)->with('model')->get();
if ($assets) $this->authorize('view', $assets[0]);
return (new AssetsTransformer)->transformAssets($assets, $assets->count());
}
}