【发布时间】:2018-03-27 13:00:07
【问题描述】:
我在查找如何在 CanCanCan 中检查管理员权限时遇到问题。
有
-
if user.admin?我得到未定义的方法 -
if user.is?我得到未定义的方法 if user.has_attribute?(:admin)-
if user.user_type == "admin"我得到未定义的方法
我对 has_attribute 有一些希望,但它没有帮助,即使我没有收到警报。 puts 'hey' 在控制台中证明了这一点。
我一个月前开始学习 Rails,但由于 Windows 的原因,我遇到了一些限制。我的问题可能是因为windows而出现的吗?
另一方面,
if user.present?有效,它再次带来了一些希望。
我的用户模型:
class User < ApplicationRecord
# Include default devise modules. Others available are:
# :confirmable, :lockable, :timeoutable and :omniauthable
devise :database_authenticatable, :registerable,
:recoverable, :rememberable, :trackable, :validatable
has_many :posts, dependent: :destroy
end
还有数据库字段
create_table "active_admin_comments", force: :cascade do |t|
t.string "namespace"
t.text "body"
t.string "resource_type"
t.integer "resource_id"
t.string "author_type"
t.integer "author_id"
t.datetime "created_at", null: false
t.datetime "updated_at", null: false
t.index ["author_type", "author_id"], name: "index_active_admin_comments_on_author_type_and_author_id"
t.index ["namespace"], name: "index_active_admin_comments_on_namespace"
t.index ["resource_type", "resource_id"], name: "index_active_admin_comments_on_resource_type_and_resource_id"
end
create_table "admin_users", force: :cascade do |t|
t.string "email", default: "", null: false
t.string "encrypted_password", default: "", null: false
t.string "reset_password_token"
t.datetime "reset_password_sent_at"
t.datetime "remember_created_at"
t.integer "sign_in_count", default: 0, null: false
t.datetime "current_sign_in_at"
t.datetime "last_sign_in_at"
t.string "current_sign_in_ip"
t.string "last_sign_in_ip"
t.datetime "created_at", null: false
t.datetime "updated_at", null: false
t.index ["email"], name: "index_admin_users_on_email", unique: true
t.index ["reset_password_token"], name: "index_admin_users_on_reset_password_token", unique: true
end
create_table "posts", force: :cascade do |t|
t.string "title"
t.text "body"
t.datetime "created_at", null: false
t.datetime "updated_at", null: false
t.string "image_file_name"
t.string "image_content_type"
t.integer "image_file_size"
t.datetime "image_updated_at"
t.integer "author_id"
end
create_table "users", force: :cascade do |t|
t.string "email", default: "", null: false
t.string "encrypted_password", default: "", null: false
t.string "reset_password_token"
t.datetime "reset_password_sent_at"
t.datetime "remember_created_at"
t.integer "sign_in_count", default: 0, null: false
t.datetime "current_sign_in_at"
t.datetime "last_sign_in_at"
t.string "current_sign_in_ip"
t.string "last_sign_in_ip"
t.datetime "created_at", null: false
t.datetime "updated_at", null: false
t.index ["email"], name: "index_users_on_email", unique: true
t.index ["reset_password_token"], name: "index_users_on_reset_password_token", unique: true
end
来自 application_controller.rb
def access_denied(exception)
respond_to do |format|
format.json { head :forbidden, content_type: 'text/html' }
format.html { redirect_to main_app.root_url, notice: exception.message }
end
end
编辑
我想了一会儿@mrzasa 建议的代码会带来一个解决方案,因为我没有更多的警报。这是因为我的能力。rb:
if user.present?
if user.admin?
puts 'hey admin'
can :manage, :all
end
can :read, all
can :manage, Post, :author_id => user.id
puts 'hey user'
end
如果我评论
# if user.present?,警报undefined method 'admin?'会再次出现。 user.present 有效的证明,但在这里说没有用户,直到我以用户身份在管理面板之外登录,然后我可以在控制台中看到 puts。但我无法执行任何操作,除非我向任何用户声明can :manage, :all。
在这个阶段,我添加了user ||= User.new 以在检查管理员之前创建一个用户实例。即使我允许任何访问者以管理员身份登录,user.admin?从未验证过,除非我在 user.rb 中将 def admin? 设置为 true
我看到很多人使用 Cancancan 来定义角色。也许我应该去争取它...
编辑 2
有效!从安装 Cancancan 到添加@mrzasa,我再次对其进行了研究。这一次,主动管理员了解管理员?来自 AdminUser 类,昨天不是这样。美妙的是,我没有更改任何代码行,除了注释
# user ||= User.new以获得预期的结果。
【问题讨论】:
-
你能不能显示
User模型有哪些字段? -
还有数据库字段?
标签: ruby-on-rails ruby ruby-on-rails-5 cancan