]> git.openstreetmap.org Git - rails.git/blobdiff - app/controllers/application_controller.rb
Allow abilities that require no login for token based access
[rails.git] / app / controllers / application_controller.rb
index 0411f75c425bfe8621f5716841a55db9ea6c5316..d4bbc1f9b7147ada16f015a77f73a0fb56168aac 100644 (file)
@@ -448,7 +448,7 @@ class ApplicationController < ActionController::Base
   def current_ability
     # Use capabilities from the oauth token if it exists and is a valid access token
     if Authenticator.new(self, [:token]).allow?
   def current_ability
     # Use capabilities from the oauth token if it exists and is a valid access token
     if Authenticator.new(self, [:token]).allow?
-      Capability.new(current_token)
+      Ability.new(nil).merge(Capability.new(current_token))
     else
       Ability.new(current_user)
     end
     else
       Ability.new(current_user)
     end