blob: 38aeade3ac77211ea89a9b47b25f1983e6c714d9 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
|
class ApplicationController < ActionController::Base
# Prevent CSRF attacks by raising an exception.
# For APIs, you may want to use :null_session instead.
#protect_from_forgery with: :exception
protect_from_forgery with: :null_session
before_action :authorize!
private
def authorize!
redirect_to new_session_path if current_user.nil?
end
def current_user
return nil if session[:x].blank?
@current_user ||= User.find(session[:x])
end
end
|