A mountable Rails engine for authorization: permissions auto-derived from controller actions, roles as editable data, per-record scoped roles, a separation-of-duties veto, and an ambient authorization context that makes allowed_to? work identically in controllers, views, and components. BETA (pre-1.0): the core is built and security-hardened; general availability is gated on one real-world enforce bake. Adopt it, run report mode, and send feedback. See the README and the issue tracker (#116).
Required Ruby Version
>= 3.2
Authors
David Teren
Versions
-
0.5.1
-
source
- 0.5.1 source August 12, 2026 (152 KB)
-
-
0.5.0
-
source
- 0.5.0 source August 12, 2026 (151 KB)
-