public async Task <ActionResult> UpdateExerciseCodeReview(string courseId, int reviewId, string comment) { var review = slideCheckingsRepo.FindExerciseCodeReviewById(reviewId); if (!string.Equals(review.ExerciseChecking.CourseId, courseId, StringComparison.OrdinalIgnoreCase)) { return(new HttpStatusCodeResult(HttpStatusCode.Forbidden)); } if (review.AuthorId != User.Identity.GetUserId()) { return(new HttpStatusCodeResult(HttpStatusCode.Forbidden)); } await slideCheckingsRepo.UpdateExerciseCodeReview(review, comment); return(Json(new { status = "ok" })); }