A mountable Rails engine for authorization: permissions auto-derived from controller actions, roles as editable data, per-record scoped roles, a separation-of-duties veto, and an ambient authorization context that makes allowed_to? work identically in controllers, views, and components. BETA (pre-1.0): the core is built and security-hardened; general availability is gated on one real-world enforce bake. Adopt it, run report mode, and send feedback. See the README and the issue tracker (#116).

Required Ruby Version

>= 3.2

Authors

David Teren

Versions

  1. 0.5.1 August 12, 2026 (152 KB)
  2. 0.5.0 August 12, 2026 (151 KB)
Show all versions (6 total)

Pushed by

SHA 256 checksum