On Miércoles, 2 de Junio de 2010 09:31:36 stephen murdoch escribió:
> I have a User resource and running on active_scaffold.  Usrs are
> either admins, or they are not admins.
> I've set it up so that admins can delete and create users.
>
> I want to allow non-admins to edit their own user details but no-one
> elses.
>
> It's easy enough to block non-admins from using the update action with
> the following code:
>
> def update_authorized?
>   self.is_admin?
> end
>
> but I don't want to block them from editing their own details.
>
> I'm having trouble specifiying the owner of the user record in the
> active_scaffold table.

I prefer to set authorization code in the model. If the model where you set 
authorization is User, it would be:
def authorized_for_update?
  current_user.is_admin? or self == current_user
end

If model where you set authorization is not user, but it has an association 
with user, it would be:
def authorized_for_update?
  current_user.is_admin? or self.user == current_user
end


>
> I would like to loop through the list of users and for each one,
> evaluate whether or not the current user is the same person as the
> user mentioned in that particular record/row....  and then obviously
> allow them to have update rights.
>
> My site uses authlogic if it helps..
>
> Would anyone have any tips on how to do that?

-- 
Sergio Cambra .:: entreCables S.L. ::.
Mariana Pineda 23, 50.018 Zaragoza
T) 902 021 404 F) 976 52 98 07 E) [email protected]

-- 
You received this message because you are subscribed to the Google Groups 
"ActiveScaffold : Ruby on Rails plugin" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/activescaffold?hl=en.

Reply via email to