If all you want to do is to prevent a user from deleting something
they are authorized to view, but not delete, then that code is all you
need.

If, however, you want to prevent a savvy user, or a curious user, or a
malicious user, from changing the URL and accessing data they are NOT
authorized to even view (let alone edit or delete), then you need a
more robust approach in the beforeFilter.

It just depends on your application and your design goals.

On Oct 9, 11:14 am, Simon <[email protected]> wrote:
> Thank you Brian thats what i was looking for
>
> On Oct 9, 9:04 am, brian <[email protected]> wrote:
>
> > On Fri, Oct 9, 2009 at 11:19 AM, Simon <[email protected]> wrote:
>
> > > if that code gose to controller then this should go to view but the
> > > other  users will see this link
> > > <?php echo $html->link(__('Delete', true), array('action'=>'delete',
> > > $comment['Comment']['id']), null, sprintf(__('Are you sure you want to
> > > delete # %s?', true), $comment['Comment']['id'])); ?>
>
> > if ($comment['Comment']['user_id'] == $session->read('Auth.User.id'))
> > {
> >     echo $html->link(__('Delete', true), array('action'=>'delete',
> > $comment['Comment']['id']), null, sprintf(__('Are you sure you want to
> > delete # %s?', true), $comment['Comment']['id']));
>
> > }- Hide quoted text -
>
> > - Show quoted text -
>
>
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"CakePHP" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/cake-php?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to