From: Jacob Fugal Date: 2005-12-07T01:54:57+09:00 Subject: Re: getting around access control On 12/6/05, ara.t.howard@noaa.gov wrote: > yeah... technically that works. what i'm doing is having handlered register > with a controller to process requests based on mime_type. the handler really > needs to be run in the context of the controller to access all the good stuff > there but which 'good stuff' is not know a priori so i can't really use this > approach. also, it's probably bad mojo to start making methods public that > should be private on an object that's directly exposed to the web ;-) Good points, especially the last one. Since all public methods of a controller are exposed as actions that can be invoked (assuming a route exists) from outside, you probably don't want them public. :) And upgrading the protection from protected to private (since your code would work with private methods) could possibly cause problems with other code that should have access but wouldn't. I guess you're stuck for now. :( Jacob Fugal