I am trying to set up a "manager" system, where some users are able to create and modify other users under their control. I am running into problems allowing managers to create new users. In the new user page I am getting a Hobo::PermissionDeniedError. I can get the new user page to work, it I set the view_permitted? method to return true. But this is not acceptable because I only want managers to be able to view other users under their control. Why should the new user page have anything to do with the view_permitted? method? Can I change the view_permitted? method to keep the other restrictions but allow new users?
These are my permission functions now: def view_permitted?(field) acting_user == self || acting_user.administrator? || managed_by_is? (acting_user) end def create_permitted? acting_user.manager? end Manager is a bool field that indicates a User is a manager. There is a belongs_to/has_many pair called managed_by/managed to indicate who manages who. Thanks. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Hobo Users" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/hobousers?hl=en -~----------~----~----~----~------~----~------~--~---
