aboutsummaryrefslogtreecommitdiffstats
path: root/sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb
diff options
context:
space:
mode:
authorSimon Brandhof <simon.brandhof@gmail.com>2011-10-20 14:57:03 +0200
committerSimon Brandhof <simon.brandhof@gmail.com>2011-10-20 14:58:49 +0200
commitb9a8170e294973750cd9e332f7c98a49dececaf1 (patch)
tree2c332875257383021147592e3bf35e708ce6b615 /sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb
parentdb17c3926fbb6ec5169c7f4d67c9d8087bc67a05 (diff)
downloadsonarqube-b9a8170e294973750cd9e332f7c98a49dececaf1.tar.gz
sonarqube-b9a8170e294973750cd9e332f7c98a49dececaf1.zip
SONAR-2771 new URL /widget : improve error handling and security
Some helper methods have been added to simplify error handling : bad_request(message), not_found(message) and access_denied.
Diffstat (limited to 'sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb')
-rw-r--r--sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb6
1 files changed, 3 insertions, 3 deletions
diff --git a/sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb b/sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb
index 76a404306d6..57108dc01e9 100644
--- a/sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb
+++ b/sonar-server/src/main/webapp/WEB-INF/app/controllers/settings_controller.rb
@@ -26,7 +26,7 @@ class SettingsController < ApplicationController
verify :method => :post, :only => ['update'], :redirect_to => {:action => :index}
def index
- return access_denied unless is_admin?
+ access_denied unless is_admin?
load_properties(false)
@category ||= 'general'
end
@@ -34,10 +34,10 @@ class SettingsController < ApplicationController
def update
if params[:resource_id]
project=Project.by_key(params[:resource_id])
- return access_denied unless (project && is_admin?(project))
+ access_denied unless (project && is_admin?(project))
resource_id=project.id
else
- return access_denied unless is_admin?
+ access_denied unless is_admin?
resource_id=nil
end