diff options
author | Robin Houston <robin.houston@gmail.com> | 2012-05-28 15:22:46 +0100 |
---|---|---|
committer | Robin Houston <robin.houston@gmail.com> | 2012-06-06 19:34:58 +0100 |
commit | fd7b5b6006e6528372e8d6fb0c888e21848b1acf (patch) | |
tree | 767d4a05f23d86d93713c0230aaa64733973950f /app/controllers/api_controller.rb | |
parent | 8e390112010abe9bb0a1831bae1ae66fcac17d7f (diff) |
API: test also for refusal conditions
The API must not allow people to update requests that they shouldn’t,
i.e. only requests that were created by the same public body, using
the API, can be added to using the API.
Diffstat (limited to 'app/controllers/api_controller.rb')
0 files changed, 0 insertions, 0 deletions