Skip to content

Controller

authorize()

authorize() — returns any

Available in: controller Category: Authorization Functions

Authorizes the current user for an action on a record by dispatching to the record’s policy (app/policies/Policy.cfc). Throws Wheels.NotAuthorized (HTTP 403) when the policy denies, and returns the record unchanged when it allows so the call can be inlined: function update() { post = authorize(model(“Post”).findByKey(params.key)); post.update(params.post); } A missing policy class throws Wheels.Policy.NotDefined in development and testing (loud, Pundit-style, to catch typos) and silently denies in production — the same environment posture as tableName() (##3079). A policy class that lacks a method for the action throws Wheels.Policy.UnknownAction (a typo, not a deny). Reserved init and scope still deny as Wheels.NotAuthorized. Only boolean true grants.

NameTypeRequiredDefaultDescription
recordanyyes—The model instance (or model class / model name string) to authorize against.
actionstringno—The policy method to dispatch. Defaults to the current params.action, resolved at call time.