- Add ActorIsAdmin policy check (admin permission set only) - User: policy action(:update_user) forbid_unless + authorize_if ActorIsAdmin - User: primary :update action accept [:email] for non-admin profile edit |
||
|---|---|---|
| .. | ||
| actor_is_admin.ex | ||
| custom_field_value_create_scope.ex | ||
| has_permission.ex | ||