Not that it should be any different in effect, but try: def view_permitted?(field) creator_is? acting_user or new_record? end
Saves a db call if creator isn't already loaded. The collection for select-many doesn't do any prefiltering so you will probably want to modify the options to only grab the relevant ones anyway. Still, I'd make sure the permissions were working right first before doing that. On Nov 17, 11:40 am, Mark Sobkowicz <[email protected]> wrote: > I can't get this to work. Let me try to be more specific. I have models > Recipe, Tag, User, and TagAssignment. > > Recipe belongs to :creator, :class_name = "User" > Tag belongs to :creator, :class_name = "User" > Recipe has many Tags through TagAssignment (and vice-versa) > > The page is the edit page of Recipe. When I add "tags" to the field-list > for the edit page, what I see depends on what is in the view_permitted? of > Tag. If this returns true, I see the neat popupmenu with a list of tags and > buttons to delete the tags. But it shows everyones tags. > > If I put the suggested code in the view_permitted, the popup doesn't show > up at all. > > I've been looking at the definition of the <select-many> tag. Since it has > the line > options ||= this_field_reflection.klass.all(:conditions > =>this.conditions).select {|x| can_view?(x)} > I figured can_view?(x) means by default it checks view_permitted for each of > its collection, but that is not what seems to happen. Could I put a > selector in the show controller for recipe? > > Or could I modify <select-many> to change which items it will show? > > On Nov 17, 2010, at 12:42 PM, Peter Ehrlich wrote: > > > So I'm not sure which model you're pulling these permissions method > > from, but at any rate it sounds like you need field-specific > > permissions, if only tags are not showing. Perhaps something inspired > > by this? > > > def view_permitted?(field) > > return true if :tag == field and acting_user == tag.creator > > end -- You received this message because you are subscribed to the Google Groups "Hobo Users" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/hobousers?hl=en.
