Hello,

I need to update some tables in my database when somebody signs up as a user.

Originally, I had the updates in the User::after_create.  However, the current 
user at that point is guest and is prohibited from updating those records by 
the hobo permission system.

So, I moved the updates to the to activate step of the User lifecycle.  The 
updates still failed because the the active_user is still Guest.  

This got me to thinking.  Is the person using the application considered to be 
authenticated if he/she can successfully activate a User?
If so, how come the acting_user is not set (to self) in the activate step?
If not, how come the person is not redirected to the login page?
Thoughts?
A related question:  if I lose my activation key, how can I get it back or 
restart the process?  Do I have to ask the administrator to remove my User 
record?
A little bit more off topic:  If I ask for a password reset and go in and reset 
may password, can someone who has found my password_reset key (e.g. from 
reading my email) be able to reuse the key to change my password and get 
control of my User?
Regards,
Henry
                                                                                
                                                                                
                        
-- 

Henry Baragar
Instantiated Software

--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Hobo 
Users" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/hobousers?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to