diff --git a/app/controllers/people_controller.rb b/app/controllers/people_controller.rb index 6ada5bfe1..1e5ef5c23 100644 --- a/app/controllers/people_controller.rb +++ b/app/controllers/people_controller.rb @@ -17,7 +17,19 @@ class PeopleController < ApplicationController end def show - @person = current_user.visible_person_by_id(params[:id]) + begin + @person = current_user.visible_person_by_id(params[:id]) + rescue BSON::InvalidObjectId + flash[:error] = "Person not found." + redirect_to people_path + return + end + unless @person + flash[:error] = "Person not found." + redirect_to people_path + return + end + @profile = @person.profile @aspects_with_person = current_user.aspects_with_person(@person) @aspects_dropdown_array = current_user.aspects.collect{|x| [x.to_s, x.id]} diff --git a/spec/controllers/people_controller_spec.rb b/spec/controllers/people_controller_spec.rb index c2af4cc93..ab15625d0 100644 --- a/spec/controllers/people_controller_spec.rb +++ b/spec/controllers/people_controller_spec.rb @@ -22,4 +22,12 @@ describe PeopleController do it 'should go to the current_user show page' do get :show, :id => @user.person.id end + + it "doesn't error out on an invalid id" do + get :show, :id => 'delicious' + end + + it "doesn't error out on a nonexistent person" do + get :show, :id => @user.id + end end