DEV Community

acuevasd
acuevasd

Posted on

Auth reviews

  • :index,:show,:new,:edit are the get routes
  • Levels: route (for everybody), controller (for some people)
  • We always should review authorization for every action, not just hide the routes. But always, don't show people things they should not be able to see

Top comments (0)