harumasa-iino / portfolio

1 stars 0 forks source link

room/:id アクセス制限 #106

Closed harumasa-iino closed 7 months ago

harumasa-iino commented 7 months ago

RoomsController の show アクションにセッションIDの確認ロジックを追加します。

# app/controllers/rooms_controller.rb
class RoomsController < ApplicationController
  def show
    @room = Room.find(params[:id])
    unless @room.session_id == session[:session_id]
      redirect_to root_path, alert: 'アクセス権限がありません。'
    end
  end
end