I am trying to set up a "manager" system, where some users are able to
create and modify other users under their control.  I am running into
problems allowing managers to create new users.  In the new user page
I am getting a Hobo::PermissionDeniedError.
I can get the new user page to work, it I set the view_permitted?
method to return true.  But this is not acceptable because I only want
managers to be able to view other users under their control.
Why should the new user page have anything to do with the
view_permitted? method?
Can I change the view_permitted? method to keep the other restrictions
but allow new users?

These are my permission functions now:
def view_permitted?(field)
  acting_user == self || acting_user.administrator? || managed_by_is?
(acting_user)
end
def create_permitted?
  acting_user.manager?
end

Manager is a bool field that indicates a User is a manager.
There is a belongs_to/has_many pair called managed_by/managed to
indicate who manages who.

Thanks.
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups "Hobo 
Users" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/hobousers?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to