On 5 August 2010 13:44, bingo bob <[email protected]> wrote: > If I can ask a more direct question. > > How do I secure my controller so only baby name owners can access their > baby names? Am I on the right lines?
I have not looked at your code but assuming that User has_many :baby_names then only allow a get of baby names to find those for the current user. So specify a condition of baby_names.user is current user in the find. Colin -- You received this message because you are subscribed to the Google Groups "Ruby on Rails: Talk" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/rubyonrails-talk?hl=en.

