A mountable Rails engine for authorization: permissions auto-derived from controller actions, roles as editable data, per-record scoped roles, a separation-of-duties veto, and an ambient authorization context that makes allowed_to? work identically in controllers, views, and components. BETA (pre-1.0): the core is built and security-hardened; general availability is gated on one real-world enforce bake. Adopt it, run report mode, and send feedback. See the README and the issue tracker (#116).

Required Ruby Version

>= 3.2

Authors

David Teren

Versions

  1. 0.5.1
    1. source

      1. 0.5.1 source August 12, 2026 (152 KB)
  2. 0.5.0
    1. source

      1. 0.5.0 source August 12, 2026 (151 KB)
Show all versions (6 total)

Pushed by

SHA 256 checksum