- Add ActorIsAdmin policy check (admin permission set only) - User: policy action(:update_user) forbid_unless + authorize_if ActorIsAdmin - User: primary :update action accept [:email] for non-admin profile edit |
||
|---|---|---|
| .. | ||
| user | ||
| accounts.ex | ||
| token.ex | ||
| user.ex | ||
| user_identity.exs | ||