diff --git a/app/controllers/projects/projects_controller.rb b/app/controllers/projects/projects_controller.rb index 1ec982a6e..38b1c595e 100644 --- a/app/controllers/projects/projects_controller.rb +++ b/app/controllers/projects/projects_controller.rb @@ -2,7 +2,7 @@ class Projects::ProjectsController < Projects::BaseController include ProjectsHelper before_filter :authenticate_user! - load_and_authorize_resource :id_param => :project_name, :collection => :possible_forks # to force member actions load + load_and_authorize_resource :id_param => :project_name # to force member actions load before_filter :who_owns, :only => [:new, :create, :mass_import, :run_mass_import] def index diff --git a/app/models/ability.rb b/app/models/ability.rb index 30cde50a3..5f3d2c7ae 100644 --- a/app/models/ability.rb +++ b/app/models/ability.rb @@ -31,6 +31,7 @@ class Ability can :show, Group can :show, User + can :possible_forks, Project if user.guest? # Guest rights # can [:new, :create], RegisterRequest