* New suspend user API endpoint
* Restrict admin access only to suspend action
* Add suspended? check on new endpoint spec
* Replace POST with PUT action
* Replace redundant response payload with empty 200 response
* Rely on user_policy instead of before_action method
* Use alias with matching method name instead of unpublish
* Use already existing toggle_suspension_status? method in policy
* Remove manual creation of note
* Update suspend success spec