Hi Folks, I have a scaffold which shows strings, and I'm using it to expose a REST API for developers who will access/modify the strings.
the strings belong to a project, which in turn belongs to a user I'm using conditions_for_collection to show only the strings that belong to users: def conditions_for_collection ['projects.user_id = (?)', current_user.id] end and I control access to update/destroy/create in my model before_destroy :check_this_is_owner before_update :check_this_is_owner before_create :check_create_project_permission which leaves one hole - any user can still use show/:id to show any string whether it is theirs or now. e.g. I can go to site/strings/4 which will show string 4 - even though string 4 belongs to a project of which I am not the owner Is there a standard way to prevent this? thanks in advance Rob --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "ActiveScaffold : Ruby on Rails plugin" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/activescaffold?hl=en -~----------~----~----~----~------~----~------~--~---
