This is good stuff, here are my notes on your code:
- Good job protecting against spoof posts by manually assigning the
author_idtocurrent_user.idand also restricting author_id from yourpost_paramsmethod. 👍 👍 👍 - Good work having
if logged_in?logic on all of the appropriate views! 👍 - When searching by id number, instead of using
find_byit is best to usefindsince that method is designed to search on the id field. [Here are the docs onfind](http://guides.rubyonrails.org/active_record_querying.html#retrieving-a-single-ob