Hey it does not look like you're checking the user sessionID after a user logs in. For example
https://robot-marketplace.herokuapp.com/users/1
https://robot-marketplace.herokuapp.com/users/2
can both be accessed after authentication.
you're admin pass for the account with the email:
[email protected]
is:
123
sorry about the penis and vag ;) but not really. CODE CAMPER!!!!!!!!