@@ -32,6 +32,7 @@ public function edit(Request $request)
32
32
33
33
// If deleting....
34
34
if ($ request ->input ('bulk_actions ' )=='delete ' ) {
35
+ $ this ->authorize ('delete ' , AssetModel::class);
35
36
$ valid_count = 0 ;
36
37
foreach ($ models as $ model ) {
37
38
if ($ model ->assets_count == 0 ) {
@@ -42,7 +43,7 @@ public function edit(Request $request)
42
43
43
44
// Otherwise display the bulk edit screen
44
45
}
45
-
46
+ $ this -> authorize ( ' update ' , AssetModel::class);
46
47
$ nochange = ['NC ' => 'No Change ' ];
47
48
return view ('models/bulk-edit ' , compact ('models ' ))
48
49
->with ('fieldset_list ' , $ nochange + Helper::customFieldsetList ())
@@ -63,7 +64,8 @@ public function edit(Request $request)
63
64
*/
64
65
public function update (Request $ request )
65
66
{
66
-
67
+ $ this ->authorize ('update ' , AssetModel::class);
68
+
67
69
$ models_raw_array = $ request ->input ('ids ' );
68
70
$ update_array = array ();
69
71
@@ -103,6 +105,8 @@ public function update(Request $request)
103
105
*/
104
106
public function destroy (Request $ request )
105
107
{
108
+ $ this ->authorize ('delete ' , AssetModel::class);
109
+
106
110
$ models_raw_array = $ request ->input ('ids ' );
107
111
108
112
if ((is_array ($ models_raw_array )) && (count ($ models_raw_array ) > 0 )) {
0 commit comments