Fall back to default_scope if an invalid foodcoop is provided

Before this change foodsoft redirect to the last active foodcoop, when
an invalid foodcoop is provided. After this change the default_scope
will be used all the time to avoid data disclosure.
This commit is contained in:
Patrick Gansterer 2017-07-08 00:07:38 +02:00
parent e366605dbe
commit c312bd5ebd
1 changed files with 1 additions and 0 deletions

View File

@ -172,6 +172,7 @@ class ApplicationController < ActionController::Base
# Set Config and database connection
FoodsoftConfig.select_foodcoop params[:foodcoop]
rescue => error
FoodsoftConfig.select_foodcoop FoodsoftConfig.config[:default_scope]
redirect_to root_url, alert: error.message
end
else