Add strong params to supporter_notes_controller

This commit is contained in:
Eric Schultz 2019-11-05 12:30:01 -06:00
parent 994b04a830
commit d5b58754ad

View file

@ -10,19 +10,26 @@ module Nonprofits
# post /nonprofits/:nonprofit_id/supporters/:supporter_id/supporter_notes # post /nonprofits/:nonprofit_id/supporters/:supporter_id/supporter_notes
def create def create
params[:supporter_note][:user_id] ||= current_user&.id params[:supporter_note][:user_id] ||= current_user&.id
render_json { InsertSupporterNotes.create([params[:supporter_note]]) } render_json { InsertSupporterNotes.create([supporter_params[:supporter_note]]) }
end end
# put /nonprofits/:nonprofit_id/supporters/:supporter_id/supporter_notes/:id # put /nonprofits/:nonprofit_id/supporters/:supporter_id/supporter_notes/:id
def update def update
params[:supporter_note][:user_id] ||= current_user&.id params[:supporter_note][:user_id] ||= current_user&.id
params[:supporter_note][:id] = params[:id] params[:supporter_note][:id] = params[:id]
render_json { UpdateSupporterNotes.update(params[:supporter_note]) } render_json { UpdateSupporterNotes.update(supporter_params[:supporter_note]) }
end end
# delete /nonprofits/:nonprofit_id/supporters/:supporter_id/supporter_notes/:id # delete /nonprofits/:nonprofit_id/supporters/:supporter_id/supporter_notes/:id
def destroy def destroy
render_json { UpdateSupporterNotes.delete(params[:id]) } render_json { UpdateSupporterNotes.delete(params[:id]) }
end end
private
def supporter_params
params.require(:supporter_note)
end
end end
end end