Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork3.3k
-
I've noticed that, with nested resources, the breadcrumbs are being generated with links to #show page of the parent resource, even if the current user is not authorized to show/edit the parent resource. This is where the issue starts: and here's where the bug is: activeadmin/app/helpers/active_admin/breadcrumb_helper.rb Lines 32 to 35 in3976a37
It checks if It also doesn't consider the case that's used in other places where |
BetaWas this translation helpful?Give feedback.
All reactions
Replies: 3 comments
-
I don't consider this a bug. For example, consider an action item (which likely contains a link) can still be displayed even if the user doesn't have access. Although it can be supplied a hook (if block) to control whether it's rendered or not. The policy should prevent not the display of the link but an unauthorized user from loading the page. If you click the link as an unauthorized user, does the page still load? |
BetaWas this translation helpful?Give feedback.
All reactions
-
I thought the default behavior was either to hide the link completely like it's the case with "Edit"/"Destroy" buttons etc. ...or, in case of In my project, users can manage sub-resources, to which they get from parent#index page. They don't have access to parent#show nor parent#edit. Does that make sense? PS the page doesn't load. It fails authorization. |
BetaWas this translation helpful?Give feedback.
All reactions
👍 1
-
I like this idea |
BetaWas this translation helpful?Give feedback.
All reactions
This discussion was converted from issue #8729 on June 01, 2025 00:12.