Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8020763
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 4, 20262026-06-04T21:46:53+00:00 2026-06-04T21:46:53+00:00

I have set up a test applications and have setup devise to take care

  • 0

I have set up a test applications and have setup devise to take care of the authentication, additionally I have set up a component where they are sent to a create profile page after registration which works well.

The problem I have is when a logged in user goes to edit they’re profile it is easy for then to change the query string and access another users data –

http://localhost:3000/profiles/1/edit

the question i have is how do I lock this down to the current user so that can only edit they’re data?

Robbie

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-04T21:46:57+00:00Added an answer on June 4, 2026 at 9:46 pm

    I would go for a before_filter.

    # in profiles controller
    class ProfilesController < ApplicationController
    
      before_filter :find_profile
      before_filter :check_if_authorized 
    
      def find_profile
        @profile = Profile.find(params[:id])
      end
    
      def check_if_authorized
        render :status => 404 and return unless current_user == @profile.user
      end
    
    end
    

    Assumptions:

    • devise model is named User
    • user has one profile
    • you’re already checking if a user is logged in
    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have an asp.net application. I have two databases set up, a test and
I have a set of test accounts that are going to be created but
I'm stress testing a web app and have set up a windows test program
HI, I want to have set configuration settings for a unit test project that
Have a JUNIT test set up as such @RunWith(SpringJUnit4ClassRunner.class) @ContextConfiguration({ /applicationContext.xml, /applicationContext-security.xml }) @TransactionConfiguration(defaultRollback
I have a set of JSPs under a folder called test and my web
I have scrip contain command line: set dir=%1 cd %dir% test.bat echo successful When
I have a simple test example that works fine, I set the drag/drop properties
I have a PowerShell module called Test.psm1. I want to set a value on
I have a set of Test::Unit tests for a Rails application. It was developed

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.