saurabhbhatia / microworld

An MIS for Microcredit Organizations and Self Help Groups
http://www.touchonelife.org/
14 stars 1 forks source link

Authorisation #9

Open naruvimama opened 14 years ago

naruvimama commented 14 years ago

Currently it is possible to use the application without actually logging in Also in the refunds for example it is possible to log a refund with a different "Feeder" Neither of these sound like a good practice, unless it is a pressing requirement.

Shouldn't we be using atleast a before filter, and disabling the arbitrary "Feeder" and may be later move to a plug-in solution for authentication?

saurabhbhatia commented 14 years ago

yeah i agree, a login only should allow the user to feed and make any changes, also the login user name should automatically become the feeder name - asif