Controller
authorize()
Signature
Section titled “Signature”authorize() — returns any
Available in: controller
Category: Authorization Functions
Description
Section titled “Description”Authorizes the current user for an action on a record by dispatching to the
record’s policy (app/policies/). Throws
Wheels.NotAuthorized (HTTP 403) when the policy denies, and returns the
record unchanged when it allows so the call can be inlined:
function update() {
post = authorize(model(“Post”).findByKey(params.key));
post.update(params.post);
}
A missing policy class throws Wheels.Policy.NotDefined in development and
testing (loud, Pundit-style, to catch typos) and silently denies in
production — the same environment posture as tableName() (##3079). A
policy class that lacks a method for the action throws
Wheels.Policy.UnknownAction (a typo, not a deny). Reserved init and
scope still deny as Wheels.NotAuthorized. Only boolean true grants.
Parameters
Section titled “Parameters”| Name | Type | Required | Default | Description |
|---|---|---|---|---|
record | any | yes | — | The model instance (or model class / model name string) to authorize against. |
action | string | no | — | The policy method to dispatch. Defaults to the current params.action, resolved at call time. |