Hi Folks,

I have a scaffold which shows strings, and I'm using it to expose a
REST API for developers who will access/modify the strings.

the strings belong to a project, which in turn belongs to a user


I'm using conditions_for_collection to show only the strings that
belong to users:

def conditions_for_collection
  ['projects.user_id = (?)', current_user.id]
end

and I control access to update/destroy/create in my model

  before_destroy :check_this_is_owner
  before_update :check_this_is_owner
  before_create :check_create_project_permission

which leaves one hole - any user can still use show/:id to show any
string whether it is theirs or now.

e.g. I can go to
site/strings/4 which will show string 4 - even though string 4 belongs
to a project of which I am not the owner

Is there a standard way to prevent this?

thanks in advance

Rob


--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"ActiveScaffold : Ruby on Rails plugin" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/activescaffold?hl=en
-~----------~----~----~----~------~----~------~--~---

  • Co... confusedVorlon
    • ... Kenny Ortmann
      • ... Sergio Cambra .:: entreCables - Symbol Servicios Informáticos S.L. ::.

Reply via email to