- Authorizer and policies: bypass for read (member_id == actor.member_id), CustomFieldValueCreateScope for create, HasPermission for read/update/destroy. - HasPermission: pass authorizer into strict_check helper; document that create must use a dedicated check (no filter). |
||
|---|---|---|
| .. | ||
| custom_field/changes | ||
| member/changes | ||
| setting/changes | ||
| custom_field.ex | ||
| custom_field_value.ex | ||
| email.ex | ||
| member.ex | ||
| membership.ex | ||
| setting.ex | ||