On Miércoles, 2 de Junio de 2010 09:31:36 stephen murdoch escribió: > I have a User resource and running on active_scaffold. Usrs are > either admins, or they are not admins. > I've set it up so that admins can delete and create users. > > I want to allow non-admins to edit their own user details but no-one > elses. > > It's easy enough to block non-admins from using the update action with > the following code: > > def update_authorized? > self.is_admin? > end > > but I don't want to block them from editing their own details. > > I'm having trouble specifiying the owner of the user record in the > active_scaffold table.
I prefer to set authorization code in the model. If the model where you set authorization is User, it would be: def authorized_for_update? current_user.is_admin? or self == current_user end If model where you set authorization is not user, but it has an association with user, it would be: def authorized_for_update? current_user.is_admin? or self.user == current_user end > > I would like to loop through the list of users and for each one, > evaluate whether or not the current user is the same person as the > user mentioned in that particular record/row.... and then obviously > allow them to have update rights. > > My site uses authlogic if it helps.. > > Would anyone have any tips on how to do that? -- Sergio Cambra .:: entreCables S.L. ::. Mariana Pineda 23, 50.018 Zaragoza T) 902 021 404 F) 976 52 98 07 E) [email protected] -- You received this message because you are subscribed to the Google Groups "ActiveScaffold : Ruby on Rails plugin" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/activescaffold?hl=en.
