Added more structure and tests to our authorization code
This commit is contained in:
13
server/policies/document.js
Normal file
13
server/policies/document.js
Normal file
@ -0,0 +1,13 @@
|
||||
// @flow
|
||||
import policy from './policy';
|
||||
import Document from '../models/Document';
|
||||
import User from '../models/User';
|
||||
|
||||
const { allow } = policy;
|
||||
|
||||
allow(
|
||||
User,
|
||||
['create', 'read', 'update', 'delete'],
|
||||
Document,
|
||||
(user, doc) => user.teamId === doc.teamId
|
||||
);
|
Reference in New Issue
Block a user