Controller
policyScope()
Signature
Section titled “Signature”policyScope() — returns any
Available in: controller
Category: Authorization Functions
Description
Section titled “Description”Narrows a collection to the records the current user may see by delegating
to the policy’s scope() method. Returns whatever the policy returns —
conventionally a chainable finder you keep composing:
function index() {
posts = policyScope(model(“Post”)).findAll(page = params.page, perPage = 25);
}
Pass the model class first and chain scopes after the call
(policyScope(model(“Post”)).active()) — a query-builder or scope chain
that is already in flight cannot be introspected for its model. When the
policy class is missing, this throws Wheels.Policy.NotDefined in
development/testing and returns a default-deny (no rows) chain in
production.
Parameters
Section titled “Parameters”| Name | Type | Required | Default | Description |
|---|---|---|---|---|
collection | any | yes | — | The model class to narrow. |