On Miércoles, 2 de Junio de 2010 09:58:49 stephen murdoch escribió: > thanks for your fast reply! > > I tried using that code before I asked and unfortunately it doesn't > prevent users from editing one-another's login details - it still lets > a normal user edit an admin's password > > I was trying to write something that would let a user see all the > other users in the list, but only be able to edit their own details > > maybe my model is wrong, I will look into that
Setting only self == current_user a user should be allowed to edit only its user. When you get that working, try to add "or current_user.is_admin?" > > On Jun 2, 8:39 am, "Sergio Cambra .:: entreCables S.L. ::." > > <[email protected]> wrote: > > On Miércoles, 2 de Junio de 2010 09:31:36 stephen murdoch escribió: > > > I have a User resource and running on active_scaffold. Usrs are > > > either admins, or they are not admins. > > > I've set it up so that admins can delete and create users. > > > > > > I want to allow non-admins to edit their own user details but no-one > > > elses. > > > > > > It's easy enough to block non-admins from using the update action with > > > the following code: > > > > > > def update_authorized? > > > self.is_admin? > > > end > > > > > > but I don't want to block them from editing their own details. > > > > > > I'm having trouble specifiying the owner of the user record in the > > > active_scaffold table. > > > > I prefer to set authorization code in the model. If the model where you > > set authorization is User, it would be: > > def authorized_for_update? > > current_user.is_admin? or self == current_user > > end > > > > If model where you set authorization is not user, but it has an > > association with user, it would be: > > def authorized_for_update? > > current_user.is_admin? or self.user == current_user > > end > > > > > I would like to loop through the list of users and for each one, > > > evaluate whether or not the current user is the same person as the > > > user mentioned in that particular record/row.... and then obviously > > > allow them to have update rights. > > > > > > My site uses authlogic if it helps.. > > > > > > Would anyone have any tips on how to do that? > > > > -- > > Sergio Cambra .:: entreCables S.L. ::. > > Mariana Pineda 23, 50.018 Zaragoza > > T) 902 021 404 F) 976 52 98 07 E) [email protected] -- Sergio Cambra .:: entreCables S.L. ::. Mariana Pineda 23, 50.018 Zaragoza T) 902 021 404 F) 976 52 98 07 E) [email protected] -- You received this message because you are subscribed to the Google Groups "ActiveScaffold : Ruby on Rails plugin" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/activescaffold?hl=en.
