diff options
Diffstat (limited to 'app/controllers/files_controller.rb')
-rw-r--r-- | app/controllers/files_controller.rb | 12 |
1 files changed, 8 insertions, 4 deletions
diff --git a/app/controllers/files_controller.rb b/app/controllers/files_controller.rb index 3cd2e77322c..bf30de565ed 100644 --- a/app/controllers/files_controller.rb +++ b/app/controllers/files_controller.rb @@ -1,12 +1,16 @@ class FilesController < ApplicationController def download note = Note.find(params[:id]) + uploader = note.attachment - if can?(current_user, :read_project, note.project) - uploader = note.attachment - send_file uploader.file.path, disposition: 'attachment' + if uploader.file_storage? + if can?(current_user, :read_project, note.project) + send_file uploader.file.path, disposition: 'attachment' + else + not_found! + end else - not_found! + redirect_to uploader.url end end end |