* Improve format and clarity of the docs [ci skip] While this change produces a lot of git noise by enacting what seems like an arbitrary linewrap on most of the files in the documentation it will result in better version control and tracking of the changes in the documentation. For example, as it currently stands, if one was to make a PR to move a comma in a sentence because each paragraph in most of the files is on a single line, that small change would look in the git history like the author had modified the entire paragraph. In reality, this author just moved a comma. This change also includes a significant number of modifications to the more article-esque docs. Many of these docs were written in a sort of stream-of-conciousness and aren't as easy to read as they could be. Hopefully this is the first of several readability changes. If we could get these docs to a more accessible reading level, we would probably see an increase in contributions. :) * Delegate markdown wrapping to Prettier * Add linewrapping explanation in the docs [ci skip]
1.9 KiB
| title |
|---|
| Roles |
Roles
What is a role?
If authorization is about who has permission to be allowed to do what you want to do, then Roles are common patterns of authorization across users - reducing the administrative overhead.
Why do I need to know about roles?
Some bugs can only be seen for users with specific roles. You will need to change the role to reproduce a problem.
How do we implement roles in DEV.to?
Roles are implemented in this application using Rolify. The list of roles can be found in app/models/role.rb and you can search for has_role in the codebase to find which pages need which roles.
A new user starts without any roles, and there is no administrative way of adding roles to users yet. To assign a user a role you will have to run commands at the console.
Example of adding permissions to a user
- open the Rails console
rails console
- after verifying the user
test_user_nameis missing theprorole we proceed to add it and then verify the role has been added:
> user = User.find_by(username: "test_user_name")
> user.has_role? :pro
=> false
> user.add_role :pro
=> #<Role:
...
name: "pro"
.. >
> user.has_role? :pro
=> true
Another common requirement is changing to the administrative role, and an example of this is found on the admin page.
Verification
A more complex query to list all the users and their roles:
User.joins(:roles).order(:id).group(:id).pluck(:id, :username, Arel.sql("array_agg(roles.name)"))