I have a User resource and running on active_scaffold.  Usrs are
either admins, or they are not admins.
I've set it up so that admins can delete and create users.

I want to allow non-admins to edit their own user details but no-one
elses.

It's easy enough to block non-admins from using the update action with
the following code:

def update_authorized?
  self.is_admin?
end

but I don't want to block them from editing their own details.

I'm having trouble specifiying the owner of the user record in the
active_scaffold table.

I would like to loop through the list of users and for each one,
evaluate whether or not the current user is the same person as the
user mentioned in that particular record/row....  and then obviously
allow them to have update rights.

My site uses authlogic if it helps..

Would anyone have any tips on how to do that?

-- 
You received this message because you are subscribed to the Google Groups 
"ActiveScaffold : Ruby on Rails plugin" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/activescaffold?hl=en.

Reply via email to