docbrown/docs/backend/roles.md
Jacob Herrington 7d0aeeefe5 Improve the clarity of the docs and fix Prettier config (#4899)
* Improve format and clarity of the docs [ci skip]

While this change produces a lot of git noise by enacting what seems
like an arbitrary linewrap on most of the files in the documentation it
will result in better version control and tracking of the changes in the
documentation.

For example, as it currently stands, if one was to make a
PR to move a comma in a sentence because each paragraph in most of the
files is on a single line, that small change would look in the git
history like the author had modified the entire paragraph. In reality,
this author just moved a comma.

This change also includes a significant number of modifications to the
more article-esque docs. Many of these docs were written in a sort of
stream-of-conciousness and aren't as easy to read as they could be.
Hopefully this is the first of several readability changes. If we could
get these docs to a more accessible reading level, we would probably see
an increase in contributions. :)

* Delegate markdown wrapping to Prettier

* Add linewrapping explanation in the docs [ci skip]
2019-11-26 08:40:53 -05:00

1.9 KiB

title
Roles

Roles

What is a role?

If authorization is about who has permission to be allowed to do what you want to do, then Roles are common patterns of authorization across users - reducing the administrative overhead.

Why do I need to know about roles?

Some bugs can only be seen for users with specific roles. You will need to change the role to reproduce a problem.

How do we implement roles in DEV.to?

Roles are implemented in this application using Rolify. The list of roles can be found in app/models/role.rb and you can search for has_role in the codebase to find which pages need which roles.

A new user starts without any roles, and there is no administrative way of adding roles to users yet. To assign a user a role you will have to run commands at the console.

Example of adding permissions to a user

  • open the Rails console
rails console
  • after verifying the user test_user_name is missing the pro role we proceed to add it and then verify the role has been added:
> user = User.find_by(username: "test_user_name")
> user.has_role? :pro
=> false

> user.add_role :pro
=> #<Role:
...
name: "pro"
.. >

> user.has_role? :pro
=> true

Another common requirement is changing to the administrative role, and an example of this is found on the admin page.

Verification

A more complex query to list all the users and their roles:

User.joins(:roles).order(:id).group(:id).pluck(:id, :username, Arel.sql("array_agg(roles.name)"))

Further Reading

  1. Rolify README.md
  2. What is the purpose of Rolify?
  3. Admin