hey, thanks a lot - got it working - perfectly - your instructions
were spot on.  i'm doing it all in the model now - will try out
tinymce later now that it's fixed

thanks

On Jun 2, 9:51 am, "Sergio Cambra .:: entreCables S.L. ::."
<[email protected]> wrote:
> On Miércoles, 2 de Junio de 2010 09:58:49 stephen murdoch escribió:
>
> > thanks for your fast reply!
>
> > I tried using that code before I asked and unfortunately it doesn't
> > prevent users from editing one-another's login details - it still lets
> > a normal user edit an admin's password
>
> > I was trying to write something that would let a user see all the
> > other users in the list, but only be able to edit their own details
>
> > maybe my model is wrong, I will look into that
>
> Setting only self == current_user a user should be allowed to edit only its
> user. When you get that working, try to add "or current_user.is_admin?"
>
>
>
>
>
> > On Jun 2, 8:39 am, "Sergio Cambra .:: entreCables S.L. ::."
>
> > <[email protected]> wrote:
> > > On Miércoles, 2 de Junio de 2010 09:31:36 stephen murdoch escribió:
> > > > I have a User resource and running on active_scaffold.  Usrs are
> > > > either admins, or they are not admins.
> > > > I've set it up so that admins can delete and create users.
>
> > > > I want to allow non-admins to edit their own user details but no-one
> > > > elses.
>
> > > > It's easy enough to block non-admins from using the update action with
> > > > the following code:
>
> > > > def update_authorized?
> > > >   self.is_admin?
> > > > end
>
> > > > but I don't want to block them from editing their own details.
>
> > > > I'm having trouble specifiying the owner of the user record in the
> > > > active_scaffold table.
>
> > > I prefer to set authorization code in the model. If the model where you
> > > set authorization is User, it would be:
> > > def authorized_for_update?
> > >   current_user.is_admin? or self == current_user
> > > end
>
> > > If model where you set authorization is not user, but it has an
> > > association with user, it would be:
> > > def authorized_for_update?
> > >   current_user.is_admin? or self.user == current_user
> > > end
>
> > > > I would like to loop through the list of users and for each one,
> > > > evaluate whether or not the current user is the same person as the
> > > > user mentioned in that particular record/row....  and then obviously
> > > > allow them to have update rights.
>
> > > > My site uses authlogic if it helps..
>
> > > > Would anyone have any tips on how to do that?
>
> > > --
> > > Sergio Cambra .:: entreCables S.L. ::.
> > > Mariana Pineda 23, 50.018 Zaragoza
> > > T) 902 021 404 F) 976 52 98 07 E) [email protected]
>
> --
> Sergio Cambra .:: entreCables S.L. ::.
> Mariana Pineda 23, 50.018 Zaragoza
> T) 902 021 404 F) 976 52 98 07 E) [email protected]

-- 
You received this message because you are subscribed to the Google Groups 
"ActiveScaffold : Ruby on Rails plugin" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/activescaffold?hl=en.

Reply via email to