Understood. Simple is good.

Yes... you would put the code in your controller and not the view.
Here is a suggestion that you would need to customize to your own
needs:

    /* Execute this code before filtering */
    function beforeFilter() {
        /* Initialize Auth component first from parent */
        parent::beforeFilter();
        if (in_array($this->action, array('view')) or
        in_array($this->action, array('edit')) or
        in_array($this->action, array('delete'))) {
                $distributor_id = $this->Distributor->field(
                   'id', array('user_id' => $this->user['id']));
                if(!$this->Dealer->find(
                                       'first',
                                        array(
                                        'conditions' => array(
                                          'distributor_id' => $distributor_id,
                                          'id' => $dealer_id
                                           ),
                                        'recursive' => -1
                                        )
                                )
                        )
                {
                $this->Session->setFlash('You are not authorized for that
information.', true);
                }
          }

Something like that. I am doing the initial find on Distributor to an
array because my results could have one that one distributor that is
authorized to view the requested dealer. Your specifications will
vary.

I'm sure this code can be improved on, but it may get you started in
the right direction.

On Oct 9, 9:36 am, Simon <[email protected]> wrote:
> yep i looked at that its pretty good i'm going to use it but for now i
> need a simple sloution like miles j's
> whats the good place for this code i tried in view but no luck maybe
> controller
> if ($comment['Comment']['user_id'] == $this->Auth->user('id')) {
> $this->Comment->delete();
>
> }
>
> On Oct 9, 7:29 am, FrederickD <[email protected]> wrote:
>
> > I believe the article has a portion of code that goes in the
> > applicable model, or even app_model to be available system wide. Then
> > other code goes in the applicable controller, not the view.
>
> > If you implement this, be sure to follow all the instructions. You
> > need both the Auth and Security components for the controller, or
> > system wide, for the way the tutorial is written. I forgot the
> > Security component at first and it didn't work at all.
>
> > There are other options on how to accomplish the same task. It is good
> > to experiment and see what works best for your application.
>
> > On Oct 9, 9:03 am, Simon <[email protected]> wrote:
>
> > > is this for view or controller if its for view i get error i changed
> > > to my model but this is the error
>
> > > Fatal error: Call to a member function User() on a non-object in
>
> > > On Oct 9, 6:02 am, FrederickD <[email protected]> wrote:
>
> > > > There is an interesting article about row-level access here that may
> > > > help too:
>
> > > >http://teknoid.wordpress.com/2009/04/22/simplistic-example-of-row-lev...
>
> > > > It may generate some other ideas for you too.
>
> > > > On Oct 8, 5:59 pm, Miles J <[email protected]> wrote:
>
> > > > > Check that the logged in user matches the owner of the post.
>
> > > > > if ($post['Comment']['user_id'] == $this->Auth->user('id')) {
> > > > > $this->Comment->delete();
>
> > > > > }
>
> > > > > On Oct 8, 2:33 pm, Simon <[email protected]> wrote:
>
> > > > > > is there any way for the users delete their own comment's  not the
> > > > > > others how can i do  that ?- Hide quoted text -
>
> > > > - Show quoted text -- Hide quoted text -
>
> > - Show quoted text -
>
>
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"CakePHP" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/cake-php?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to