diff --git a/app/controllers/application_controller.rb b/app/controllers/application_controller.rb index d83690e..096e334 100644 --- a/app/controllers/application_controller.rb +++ b/app/controllers/application_controller.rb @@ -2,4 +2,26 @@ class ApplicationController < ActionController::Base # Prevent CSRF attacks by raising an exception. # For APIs, you may want to use :null_session instead. protect_from_forgery with: :exception + + # config/initializers/pundit.rb + # Extends the ApplicationController to add Pundit for authorization. + # Modify this file to change the behavior of a 'not authorized' error. + # Be sure to restart your server when you modify this file. + module PunditHelper + extend ActiveSupport::Concern + + #included do + #include Pundit + #rescue_from Pundit::NotAuthorizedError, with: :user_not_authorized + #end + + private + + def user_not_authorized + flash[:alert] = 'Access denied.' + redirect_to (request.referrer || root_path) + end + end + + ApplicationController.send :include, PunditHelper end