mitgliederverwaltung/lib
Moritz 14fa873640 Restrict User.update_user to admin; allow :update for email only
- Add ActorIsAdmin policy check (admin permission set only)
- User: policy action(:update_user) forbid_unless + authorize_if ActorIsAdmin
- User: primary :update action accept [:email] for non-admin profile edit
2026-01-30 11:13:23 +01:00
..
accounts Restrict User.update_user to admin; allow :update for email only 2026-01-30 11:13:23 +01:00
membership CustomField policies: actor required, no system-actor fallback, error handling 2026-01-29 16:10:12 +01:00
membership_fees Use authorize?: false for integrity checks in validations 2026-01-24 02:21:09 +01:00
mv Restrict User.update_user to admin; allow :update for email only 2026-01-30 11:13:23 +01:00
mv_web Delegate can_access_page? to CheckPagePermission 2026-01-30 10:22:31 +01:00
mv.ex Add generated starter app 2025-03-18 15:05:27 +01:00
mv_web.ex Centralize role preloading in global LiveView on_mount 2026-01-22 21:36:15 +01:00