Funny how you always find a solution just after you post the question.
I fixed it by changing my permissions to:
def view_permitted?(field)
  return true if nil == id && acting_user.manager?
  acting_user == self || acting_user.administrator? || managed_by_is?
(acting_user)
end

But I still don't get why view_permitted? is getting called on a new
user.

I am also having a problem getting a Users tab to appear in my
navigation bar.  My main-nav tag in pages.dryml shows a Users nav-
item.  But it does not actually show up on my page...  What could be
going wrong?

On Oct 18, 7:27 pm, oillio <[email protected]> wrote:
> I am trying to set up a "manager" system, where some users are able to
> create and modify other users under their control.  I am running into
> problems allowing managers to create new users.  In the new user page
> I am getting a Hobo::PermissionDeniedError.
> I can get the new user page to work, it I set the view_permitted?
> method to return true.  But this is not acceptable because I only want
> managers to be able to view other users under their control.
> Why should the new user page have anything to do with the
> view_permitted? method?
> Can I change the view_permitted? method to keep the other restrictions
> but allow new users?
>
> These are my permission functions now:
> def view_permitted?(field)
>   acting_user == self || acting_user.administrator? || managed_by_is?
> (acting_user)
> end
> def create_permitted?
>   acting_user.manager?
> end
>
> Manager is a bool field that indicates a User is a manager.
> There is a belongs_to/has_many pair called managed_by/managed to
> indicate who manages who.
>
> Thanks.
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Hobo 
Users" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/hobousers?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to