summaryrefslogtreecommitdiff
path: root/app/controllers/application_controller.rb
blob: 38aeade3ac77211ea89a9b47b25f1983e6c714d9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
class ApplicationController < ActionController::Base
  # Prevent CSRF attacks by raising an exception.
  # For APIs, you may want to use :null_session instead.
  #protect_from_forgery with: :exception
  protect_from_forgery with: :null_session
  before_action :authorize!

  private

  def authorize!
    redirect_to new_session_path if current_user.nil?
  end

  def current_user
    return nil if session[:x].blank?
    @current_user ||= User.find(session[:x])
  end
end