array( // 'panels' => array('variables'=>false) ), 'Session', 'PathResolver', 'Auth'); var $layout = "new"; function beforeFilter() { parent::beforeFilter(); $this->Auth->autoRedirect = false; $this->Auth->authorize = 'controller'; $this->Auth->userScope = array('User.activated' => true, 'User.confirm_hash' => null); $this->Auth->loginAction = array('admin' => false, 'controller' => 'users', 'action' => 'login'); if ($this->Auth->user('role') == "admin") $this->Auth->allow("*"); else if ($this->Auth->user()) { // $this->Auth->allow('index', 'view', 'add', 'delete', 'edit'); foreach ($this->methods as $method) if (mb_strpos($method, 'admin_') !== 0) $this->Auth->allow($method); } } function isAuthorized() { /* if (isset($this->params['prefix']) && $this->params['prefix'] == "admin" && $this->Auth->user('role') != "admin") { return false; } return true;*/ $action = $this->params['action']; $allowedActions = array_map('strtolower', $this->Auth->allowedActions); $isAllowed = ( $this->Auth->allowedActions == array('*') || in_array($action, $allowedActions) ); // $this->log($isAllowed); return $isAllowed; } }