I have this in my app_controller

var $components = array('Session', 'Auth');

function beforeFilter(){
        parent::beforeFilter();


        # thanks to 
http://padariadodenilson.wordpress.com/2010/10/04/criando-uma-area-administrativa-com-cakephp/
        if (isset($this->params['admin'])) {
            $this->Auth->deny('*');
        } else {
            $this->Auth->allow('*');
        }

        $this->Auth->fields = array('username' => 'name', 'password'
=> 'password');
        //$this->Auth->loginError = "No, you fool!  That's not the
right password!";
        //$this->Auth->loginAction = array('admin' => false,
'controller' => 'users', 'action' => 'login');
        //$this->Auth->loginRedirect = array('controller' =>
'usuarios', 'action' => 'afterLogin');
        $this->Auth->authError = "Você precisa estar logado para
entrar no sistema.";
    }

My routes config are:

Router::connect("/admin/:controller/:action/*", array('prefix' =>
'admin', 'admin' => true));


this way admin methods are protected but if I take off that condition
e Auth allows really everything,
thanks for helping

On 12 nov, 15:50, cricket <[email protected]> wrote:
> On Thu, Nov 11, 2010 at 11:44 PM, huoxito <[email protected]> wrote:
> > Thats what I thought as well, but it doesnt happen,
>
> > If I just let $this->Auth->allow(‘*’) in my app_controller all actions
> > are accessible without being logged in, even my admin_* methods
>
> Perhaps Auth isn't properly configured in
> AppController::beforeFilter(). Could you post that?

Check out the new CakePHP Questions site http://cakeqs.org and help others with 
their CakePHP related questions.

You received this message because you are subscribed to the Google Groups 
"CakePHP" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[email protected] For more options, visit this group at 
http://groups.google.com/group/cake-php?hl=en

Reply via email to