Let an administrator view an account as its owner. Read-only by default (two layers: no non-GET requests, and ActiveRecord writes refused), re-validated from the database on every request so revoked consent bites on the next click, time-boxed server-side, and logged in words the account owner can read. Stores its state in a signed cookie rather than the Rails session, so an edge-cached site stays cached. Built for the Rails 8 authentication generator; works with anything that can answer "who is signed in".

Required Ruby Version

>= 3.3

Authors

Ed

Versions

  1. 0.1.0 September 22, 2026 (19 KB)

Pushed by

SHA 256 checksum