Feature #3848 » 0002-Access-params-time_entry-only-if-editing-a-time-entr.patch
| app/controllers/issues_controller.rb | ||
|---|---|---|
| 177 | 177 | end | 
| 178 | 178 | |
| 179 | 179 | if request.post? | 
| 180 | if User.current.allowed_to?(:edit_time_entries, @project) | |
| 180 |       if User.current.allowed_to?(:edit_time_entries, @project) and params[:time_entry] | |
| 181 | 181 | user = User.find(Hash[params[:time_entry].to_a]["user_id"].to_i) | 
| 182 | 182 | else | 
| 183 | 183 | # TODO: Maybe I should throw an exception if the current user |