active scaffold conditions for collection is only supposed to be used to
limit the list, not to be used for not allowing viewing.

you need to but a before filter on the show action that directs the user
away if they don't own the project.  you should change the before destroy
before update and before creates to also use a before filter.

On Mon, Mar 23, 2009 at 7:26 AM, confusedVorlon <[email protected]>wrote:

>
> Hi Folks,
>
> I have a scaffold which shows strings, and I'm using it to expose a
> REST API for developers who will access/modify the strings.
>
> the strings belong to a project, which in turn belongs to a user
>
>
> I'm using conditions_for_collection to show only the strings that
> belong to users:
>
> def conditions_for_collection
>  ['projects.user_id = (?)', current_user.id]
> end
>
> and I control access to update/destroy/create in my model
>
>  before_destroy :check_this_is_owner
>  before_update :check_this_is_owner
>  before_create :check_create_project_permission
>
> which leaves one hole - any user can still use show/:id to show any
> string whether it is theirs or now.
>
> e.g. I can go to
> site/strings/4 which will show string 4 - even though string 4 belongs
> to a project of which I am not the owner
>
> Is there a standard way to prevent this?
>
> thanks in advance
>
> Rob
>
>
> >
>

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"ActiveScaffold : Ruby on Rails plugin" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/activescaffold?hl=en
-~----------~----~----~----~------~----~------~--~---

  • Co... confusedVorlon
    • ... Kenny Ortmann
      • ... Sergio Cambra .:: entreCables - Symbol Servicios Informáticos S.L. ::.

Reply via email to