From 706af36da9d73e3a3427d981df4ceb34984e5d37 Mon Sep 17 00:00:00 2001
From: Sunny Ripert <sunny@sunfox.org>
Date: Fri, 3 Feb 2012 15:05:03 +0100
Subject: [PATCH] Hide other people's data exports

---
 app/controllers/teambox_datas_controller.rb | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/app/controllers/teambox_datas_controller.rb b/app/controllers/teambox_datas_controller.rb
index 5e4ebd64c5..11f7cb2e61 100644
--- a/app/controllers/teambox_datas_controller.rb
+++ b/app/controllers/teambox_datas_controller.rb
@@ -13,6 +13,8 @@ def index
   end
   
   def show
+    head(:forbidden) and return unless @data.downloadable?(current_user)
+
     respond_to do |f|
       if @data.type_name == :import and @data.need_data? and @data.data == nil
         @data.status_name = :uploading