- Add ActorIsAdmin policy check (admin permission set only) - User: policy action(:update_user) forbid_unless + authorize_if ActorIsAdmin - User: primary :update action accept [:email] for non-admin profile edit |
||
|---|---|---|
| .. | ||
| checks | ||
| actor.ex | ||
| authorization.ex | ||
| permission_sets.ex | ||
| role.ex | ||