hey, thanks a lot - got it working - perfectly - your instructions were spot on. i'm doing it all in the model now - will try out tinymce later now that it's fixed
thanks On Jun 2, 9:51 am, "Sergio Cambra .:: entreCables S.L. ::." <[email protected]> wrote: > On Miércoles, 2 de Junio de 2010 09:58:49 stephen murdoch escribió: > > > thanks for your fast reply! > > > I tried using that code before I asked and unfortunately it doesn't > > prevent users from editing one-another's login details - it still lets > > a normal user edit an admin's password > > > I was trying to write something that would let a user see all the > > other users in the list, but only be able to edit their own details > > > maybe my model is wrong, I will look into that > > Setting only self == current_user a user should be allowed to edit only its > user. When you get that working, try to add "or current_user.is_admin?" > > > > > > > On Jun 2, 8:39 am, "Sergio Cambra .:: entreCables S.L. ::." > > > <[email protected]> wrote: > > > On Miércoles, 2 de Junio de 2010 09:31:36 stephen murdoch escribió: > > > > I have a User resource and running on active_scaffold. Usrs are > > > > either admins, or they are not admins. > > > > I've set it up so that admins can delete and create users. > > > > > I want to allow non-admins to edit their own user details but no-one > > > > elses. > > > > > It's easy enough to block non-admins from using the update action with > > > > the following code: > > > > > def update_authorized? > > > > self.is_admin? > > > > end > > > > > but I don't want to block them from editing their own details. > > > > > I'm having trouble specifiying the owner of the user record in the > > > > active_scaffold table. > > > > I prefer to set authorization code in the model. If the model where you > > > set authorization is User, it would be: > > > def authorized_for_update? > > > current_user.is_admin? or self == current_user > > > end > > > > If model where you set authorization is not user, but it has an > > > association with user, it would be: > > > def authorized_for_update? > > > current_user.is_admin? or self.user == current_user > > > end > > > > > I would like to loop through the list of users and for each one, > > > > evaluate whether or not the current user is the same person as the > > > > user mentioned in that particular record/row.... and then obviously > > > > allow them to have update rights. > > > > > My site uses authlogic if it helps.. > > > > > Would anyone have any tips on how to do that? > > > > -- > > > Sergio Cambra .:: entreCables S.L. ::. > > > Mariana Pineda 23, 50.018 Zaragoza > > > T) 902 021 404 F) 976 52 98 07 E) [email protected] > > -- > Sergio Cambra .:: entreCables S.L. ::. > Mariana Pineda 23, 50.018 Zaragoza > T) 902 021 404 F) 976 52 98 07 E) [email protected] -- You received this message because you are subscribed to the Google Groups "ActiveScaffold : Ruby on Rails plugin" group. To post to this group, send email to [email protected]. To unsubscribe from this group, send email to [email protected]. For more options, visit this group at http://groups.google.com/group/activescaffold?hl=en.
