On Miércoles, 2 de Junio de 2010 09:58:49 stephen murdoch escribió:
> thanks for your fast reply!
>
> I tried using that code before I asked and unfortunately it doesn't
> prevent users from editing one-another's login details - it still lets
> a normal user edit an admin's password
>
> I was trying to write something that would let a user see all the
> other users in the list, but only be able to edit their own details
>
> maybe my model is wrong, I will look into that

Setting only self == current_user a user should be allowed to edit only its 
user. When you get that working, try to add "or current_user.is_admin?"

>
> On Jun 2, 8:39 am, "Sergio Cambra .:: entreCables S.L. ::."
>
> <[email protected]> wrote:
> > On Miércoles, 2 de Junio de 2010 09:31:36 stephen murdoch escribió:
> > > I have a User resource and running on active_scaffold.  Usrs are
> > > either admins, or they are not admins.
> > > I've set it up so that admins can delete and create users.
> > >
> > > I want to allow non-admins to edit their own user details but no-one
> > > elses.
> > >
> > > It's easy enough to block non-admins from using the update action with
> > > the following code:
> > >
> > > def update_authorized?
> > >   self.is_admin?
> > > end
> > >
> > > but I don't want to block them from editing their own details.
> > >
> > > I'm having trouble specifiying the owner of the user record in the
> > > active_scaffold table.
> >
> > I prefer to set authorization code in the model. If the model where you
> > set authorization is User, it would be:
> > def authorized_for_update?
> >   current_user.is_admin? or self == current_user
> > end
> >
> > If model where you set authorization is not user, but it has an
> > association with user, it would be:
> > def authorized_for_update?
> >   current_user.is_admin? or self.user == current_user
> > end
> >
> > > I would like to loop through the list of users and for each one,
> > > evaluate whether or not the current user is the same person as the
> > > user mentioned in that particular record/row....  and then obviously
> > > allow them to have update rights.
> > >
> > > My site uses authlogic if it helps..
> > >
> > > Would anyone have any tips on how to do that?
> >
> > --
> > Sergio Cambra .:: entreCables S.L. ::.
> > Mariana Pineda 23, 50.018 Zaragoza
> > T) 902 021 404 F) 976 52 98 07 E) [email protected]

-- 
Sergio Cambra .:: entreCables S.L. ::.
Mariana Pineda 23, 50.018 Zaragoza
T) 902 021 404 F) 976 52 98 07 E) [email protected]

-- 
You received this message because you are subscribed to the Google Groups 
"ActiveScaffold : Ruby on Rails plugin" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/activescaffold?hl=en.

Reply via email to